712-50 Question 66
Single answerEvaluate audit results, weighing the relevancy, accuracy, and perspective of conclusions against the accumulated audit evidenceA newly appointed CISO receives an internal audit report concluding that the organization's identity and access management (IAM) program is "ineffective" and poses a high risk of unauthorized access. The conclusion is based primarily on a sample of 12 privileged accounts from one business unit, 3 of which had not been recertified within the required period. The auditors did not review compensating controls such as SIEM alerting, PAM session monitoring, or the risk-accepted exception process approved by the governance committee. Before presenting the audit results to the board audit committee, what is the MOST appropriate action for the CISO to take?
- A
Accept the audit conclusion as written because any noncompliance with privileged access recertification automatically demonstrates that the IAM program is ineffective enterprise-wide
- B
Challenge the audit conclusion by assessing whether the sample, scope, and omitted compensating controls support the severity and enterprise-wide nature of the finding before endorsing it
- C
Reject the audit report because internal audit did not test every privileged account across the organization, making the conclusion invalid
- D
Immediately downgrade the finding from high risk to low risk because monitoring controls reduce the likelihood of unauthorized access even when recertification is overdue
Show answer and explanation
Correct answer: B
Explanation
The best answer is to assess whether the audit conclusion is adequately supported by the accumulated audit evidence before endorsing it. In this scenario, the auditors identified a real control issue, but their broader conclusion that the IAM program is ineffective enterprise-wide may not be fully supported because the evidence was limited to a small sample from one business unit and did not account for compensating controls or approved exceptions. A senior security executive should weigh the relevancy of the evidence to the conclusion, the accuracy of the factual basis, and the perspective or context in which the auditors interpreted the results. This is consistent with risk-based governance practices and the principles found in internal audit standards that require conclusions to be based on sufficient, reliable, relevant, and useful information. Practical frameworks such as the IIA's International Standards for the Professional Practice of Internal Auditing and ISACA audit guidance emphasize evaluating whether evidence is sufficient and appropriate, whether sampling supports the assertion made, and whether conclusions fairly reflect the control environment and residual risk.
- A. Incorrect.
This is incorrect because isolated noncompliance does not automatically justify a broad conclusion that the entire IAM program is ineffective. A CISO should evaluate whether the auditors' conclusion is relevant, accurate, and proportionate to the evidence gathered. The sample came from a single business unit and excluded compensating controls, so endorsing an enterprise-wide high-risk conclusion without further review would be poor governance.
- B. Correct.
This is correct because the CISO's role is not to dismiss audit findings reflexively, but to evaluate whether the conclusion is supported by sufficient, appropriate evidence and whether the auditors considered context. Reviewing sample representativeness, testing scope, and omitted compensating controls helps determine whether the stated severity and enterprise-wide implication are justified. This reflects sound executive oversight of audit results and aligns with risk-based decision making.
- C. Incorrect.
This is incorrect because audits commonly rely on sampling rather than full-population testing. The issue is not that every account was not tested, but whether the sample and scope were appropriate for the conclusion drawn. Rejecting the report outright confuses reasonable assurance with absolute assurance, which is not the standard for internal audit.
- D. Incorrect.
This is incorrect because the CISO should not unilaterally re-rate a finding downward simply because compensating controls exist. Compensating controls may affect residual risk, but they do not automatically invalidate the control deficiency. The proper approach is to evaluate the full body of evidence and discuss whether the conclusion and risk rating are supported, rather than preemptively minimizing the issue.