Which of the following should be the FIRST step of an IS audit?
A. Create a flowchart of the decision branches.
B. Gain an understanding of the environment under review.
C. Perform a risk assessment.
D. Develop the audit plan.
Answer Posted / guest
Answer: B
An auditor needs to gain an understanding of the processes
prior to creating a flowchart. Based on the scope of the
audit, the IS auditor should gain an understanding of the
environment under review, and then carry out a risk
assessment. Finally, on the basis of understanding the
environment under review and the risk assessment, the IS
auditor should prepare an audit plan.
Is This Answer Correct ? | 8 Yes | 0 No |
Post New Answer View All Answers