CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 569


An IS auditor discovers a box of hard drives in a secured location that are overdue for physical destruction. The vendor responsible for this task was never made aware of these hard drives. Which of the following is the BEST course of action to address this issue?

Show Answer
Correct Answer: BD

The best course of action is to escalate the finding to the asset owner for remediation. This ensures that the responsible party is made aware of the oversight and can take immediate steps to address it. While evaluating the workflow and policies for gaps is important for long-term prevention, immediate action to rectify the current issue is critical.

Discussion

4 comments
Sign in to comment
ChangwhaOption: D
Jul 26, 2023

D. Escalate the finding to the asset owner for remediation.

3008Option: D
Nov 25, 2023

D is correct.

SwallowsOption: D
Jun 9, 2024

While evaluating the corporate asset handling policy for potential gaps (option A) is also important, escalating the finding to the asset owner for remediation ensures swift and direct action to address the immediate issue while also facilitating improvements to prevent recurrence.

InfysenthilOption: B
Jul 6, 2024

I believe B is correct. Before making any recommendation, the IS auditor should gain a good understanding of the scope of the problem and what factors caused this incident. The IS auditor should identify whether the issue was caused by managers not following procedures, or by a problem with the workflow of the automated system or a combination of the two.

Swallows
Jul 7, 2024

I agree with you. I change my selection.