Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified Information Systems Auditor CISA Question # 219 Topic 22 Discussion

Isaca Certified Information Systems Auditor CISA Question # 219 Topic 22 Discussion

CISA Exam Topic 22 Question 219 Discussion:
Question #: 219
Topic #: 22

An IS auditor believes that management has accepted a level of residual risk that is not appropriate for the organization. Which of the following is the auditor’s MOST appropriate course of action?


A.

Submit a report informing the board of management’s decision to accept the risk.


B.

Discuss the matter with IS audit management and executive management.


C.

Include management’s response to accept the risk in the audit report and take no further action.


D.

Include the risk as a finding in the audit report but do not note management’s risk acceptance.


Get Premium CISA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.