Exam IIA-CIA-Part2 All QuestionsBrowse all questions from this exam
Question 238

A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the attempt was not successful. The chief audit executive (CAE) learns of the attack in a casual conversation with an IT auditor. Which of the following actions should the CAE take?

1. Meet with the chief IT officer to discuss the report and control improvements that will be implemented as a result of the security breach, if any.

2. Immediately inform the chair of the audit committee of the security breach, because thus far only the chief IT officer is aware of the incident.

3. Meet with the IT auditor to develop an appropriate audit program to review the organization's Internet-based sales process and key controls.

4. Include the incident in the next quarterly report to the audit committee.

    Correct Answer: B

    The correct actions the CAE should take include meeting with the chief IT officer to discuss the report and potential control improvements that may be implemented as a result of the hacking attempt, and meeting with the IT auditor to develop an appropriate audit program to review the organization's Internet-based sales process and key controls. This ensures that the CAE is fully informed of the incident and subsequent actions, and that a thorough review of the relevant controls is conducted to prevent future incidents.

Discussion
John1237

Here is a typical case where the CEO is not mentioned.