Isaca Certified Information Systems Auditor CISA Question # 319 Topic 32 Discussion
CISA Exam Topic 32 Question 319 Discussion:
Question #: 319
Topic #: 32
When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the
A.
scope and methodology meet audit requirements
B.
service provider is independently certified and accredited
C.
report confirms that service levels were not violated
It is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the scope and methodology meet audit requirements. This means that the external audit report covers the same objectives, criteria, standards and procedures that the IS auditor would use to assess the service level management. This way, the IS auditor can avoid duplication of work and reduce audit costs and efforts. The service provider’s certification and accreditation, the report’s confirmation of service levels and the report’s release date are not sufficient to justify reliance on the external audit report. References: CISA Review Manual (Digital Version) , Chapter 2, Section 2.3.3.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit