CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 1218


An IS auditor has identified deficiencies within the organization's software development life cycle policies. Which of the following should be done NEXT?

Show Answer
Correct Answer: D

After identifying deficiencies within the organization's software development life cycle policies, the next logical step is to communicate the observation to the auditee. This allows the auditee the opportunity to address the identified issues and provide their perspective or take corrective action. Once this communication has taken place, the auditor can proceed with documenting the findings in the audit report, ensuring that all necessary information and responses from the auditee are included.

Discussion

5 comments
Sign in to comment
SwallowsOption: D
Apr 5, 2024

Before issuing an audit report, the auditor works with the auditee to verify the facts of the findings.

MJORGEROption: D
Mar 4, 2024

D. Communicate the observation to the auditee. Documenting the findings in the audit report is essential, but it should come after communicating the observations to the auditee. The auditee should have an opportunity to respond or take corrective action before the findings are formally documented.

marc4354345Option: C
Feb 26, 2024

C makes most sense to me.

SwallowsOption: C
Apr 5, 2024

Prior to issuing an audit report, auditor review the facts of our findings with the auditee.

SwallowsOption: D
May 29, 2024

While options such as escalating the situation to the lead auditor (option A) may be necessary in certain circumstances, it's generally advisable to start by communicating the observation to the auditee. This allows the organization to respond to the findings and take appropriate actions promptly.