CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 1145


A business has requested an audit to determine whether information stored in an application is adequately protected. Which of the following is the MOST important action before the audit work begins?

Show Answer
Correct Answer: D

Before beginning an audit to determine whether information stored in an application is adequately protected, it is most important to establish control objectives. Control objectives provide a clear set of goals and benchmarks against which the security of the application can be measured. This helps ensure that the audit is focused, efficient, and aligned with the business's compliance and security requirements. Without established control objectives, the audit could lack direction and miss critical areas of assessment.

Discussion

4 comments
Sign in to comment
updateeOption: A
Jan 13, 2024

I think that A is a more proper answer.

SibsankarOption: A
Feb 17, 2024

A is the right answer

a84nOption: A
May 6, 2024

Answer A. Assess the threat landscape.

SwallowsOption: D
Jul 15, 2024

Identifying control objectives provides a focus for the audit and sets a standard for properly assessing the state of information protection. While assessing the threat landscape is important, establishing the audit objectives should take priority.