The FINAL decision to include a material finding in a cloud audit report should be made by the:
The other options are not correct. Option A is incorrect, as the auditee's senior management is not in charge of the audit report, but rather the subject of the audit. The auditee's senior management should provide their perspective and action plans for the material findings, but they cannot decide whether to include or exclude them from the report. Option B is incorrect, as the organization's CEO is not involved in the audit process, but rather the ultimate recipient of the audit report. The organization's CEO should review and act upon the audit report, but they cannot influence the content of the report. Option D is incorrect, as the organization's CISO is not an independent party, but rather a stakeholder of the audit. The organization's CISO should support and collaborate with the cloud auditor, but they cannot make the final decision on the material findings.Reference:
ISACA Cloud Auditing Knowledge Certificate Study Guide, page 19-20.
Verona
9 hours agoRaymon
6 days agoKatina
11 days agoLilli
16 days agoMicah
21 days agoTamesha
26 days agoLatricia
1 month agoColetta
1 month agoJerlene
1 month agoJesusita
2 months agoVallie
2 months agoMari
2 months agoStefany
2 months agoFranklyn
2 months agoCordell
2 months agoMelita
3 months agoKrissy
3 months agoFausto
3 months agoEric
3 months ago