CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 215


After the merger of two organizations, which of the following is the MOST important task for an IS auditor to perform?

Show Answer
Correct Answer: C

After the merger of two organizations, the most important task for an IS auditor is to verify that access privileges have been reviewed. This process ensures that only authorized personnel have appropriate access to critical systems and data, which is crucial in protecting the confidentiality, integrity, and availability of information. Reviewing access privileges addresses immediate potential security risks that may arise from the merger, such as unauthorized access or privilege escalation, and helps to align the access controls with the new organizational structure.

Discussion

4 comments
Sign in to comment
DeeplaxmiOption: C
Sep 29, 2022

yes the IS auditor cannot update BCP or security policy.. its the work of organisation. so a and B option are ruled out. Amongst c and D, c is better choice.

ZephaniahOption: B
Sep 27, 2022

I THINK B

007GeorgeoOption: C
May 4, 2023

C. Verifying that access privileges have been reviewed

SwallowsOption: C
Jun 2, 2024

While updating the security policy (option B) is also important to reflect changes resulting from the merger, verifying access privileges takes precedence because it directly addresses security risks associated with access control, confidentiality, and data protection. By confirming that access privileges have been reviewed and adjusted as necessary, the IS auditor helps safeguard the organization's information assets and ensures compliance with security policies and regulatory requirements.