← All CCISO Flashcard Decks

Audit Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Audit Management flashcards as text
  1. When an external auditor identifies a material weakness in internal controls, what must a publicly traded company in the US do under SOX Section 404?

    Answer: Disclose the material weakness in its annual report and management's assessment

    SOX Section 404 requires management and external auditors to report on internal control effectiveness, including disclosure of any material weaknesses in the annual report.

  2. Which audit evidence type is generally considered most reliable?

    Answer: Evidence obtained directly by the auditor through observation and reperformance

    Evidence obtained directly by the auditor — through observation, inspection, or reperformance — is considered the most reliable because it is not filtered through the auditee.

  3. A CISO is conducting a gap analysis between current security controls and ISO 27001 requirements. What audit technique is being applied?

    Answer: Compliance testing

    Comparing existing controls against a standard's requirements is compliance (or conformance) testing, which determines whether controls meet defined criteria.

  4. What is the purpose of an audit work paper review by a senior auditor before report issuance?

    Answer: To verify that evidence supports findings and that conclusions are adequately documented

    Senior review of work papers ensures that findings are supported by sufficient evidence and that documentation meets quality standards before the report is issued.

  5. Which concept describes the risk that audit procedures will fail to detect a material misstatement that exists?

    Answer: Detection risk

    Detection risk is the risk that the auditor's procedures will not identify a material misstatement or control failure that actually exists.

  6. An organization uses a shared service center for financial processing. How should the CISO approach auditing controls in this shared environment?

    Answer: Obtain and review a SOC 1 or SOC 2 report from the shared service center

    A SOC 1 (Type II) or SOC 2 report from the shared service center provides independent assurance over controls at the service organization relevant to user entities.

  7. What does 'audit risk' represent in the context of a financial or compliance audit?

    Answer: The combined risk that material misstatements exist and that the auditor fails to detect them

    Audit risk is the product of inherent risk, control risk, and detection risk — the overall risk that the auditor issues an incorrect opinion.