Exam CISA All QuestionsBrowse all questions from this exam
Question 420

Which of the following findings should be of GREATEST concern to an IS auditor assessing the risk associated with end-user computing (EUC) in an organization?

    Correct Answer: C

    Insufficient processes to track ownership of each EUC application should be of the greatest concern. Without clearly defined ownership, there is a significant risk of mismanagement, lack of accountability, and potential non-compliance with regulations. This issue can lead to difficulties in tracking who is responsible for maintaining, updating, and ensuring the security of each application. Ownership is key to effective risk management, as it ensures there are designated individuals or teams accountable for the proper functioning and oversight of EUC applications.

Discussion
swmasindeOption: A

A. Lack of defined criteria for EUC applications mean no policies, procedures, processes, organization criteria

3008Option: A

A is correct.

BA27Option: A

A. Lack of defined criteria for EUC applications

MohamedAbdelaalOption: C

I think answer C is the most correct one, as the other options are already characteristics of the EUC

SwallowsOption: C

Lack of tracking of ownership leads to unclear accountability and increased risk management and compliance issues. While lack of clear standards is important, poor tracking of ownership is a particularly serious risk.

Eric0223Option: D

lacks of control is more important to my point of view than critiria .

Eric0223

but it looks like insuffcient . hmm. hard to tell