New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CRISC Exam - Topic 7 Question 95 Discussion

Actual exam question for Isaca's CRISC exam
Question #: 95
Topic #: 7
[All CRISC Questions]

Reviewing results from which of the following is the BEST way to identify information systems control deficiencies?

Show Suggested Answer Hide Answer
Suggested Answer: D

Information systems control deficiencies are the weaknesses or flaws in the design or implementation of the controls that are intended to ensure the confidentiality, integrity, availability, and reliability of the information systems and resources. Information systems control deficiencies may reduce the effectiveness or efficiency of the controls, and expose the organization to various risks, such as unauthorized access, data loss, system failure, etc.

Reviewing results from control self-assessment (CSA) is the best way to identify information systems control deficiencies, because CSA is a process of evaluating and verifying the adequacy and effectiveness of the information systems controls, using the input and feedback from the individuals or groups that are involved or responsible for the information systems activities or functions. CSA can help the organization to identify and document the information systems control deficiencies, and to align them with the organization's information systems objectives and requirements.

CSA can be performed using various techniques, such as questionnaires, surveys, interviews, workshops, etc. CSA can also be integrated with the organization's governance, risk management, and compliance functions, and aligned with the organization's policies and standards.

The other options are not the best ways to identify information systems control deficiencies, because they do not provide the same level of detail and insight that CSA provides, and they may not be relevant or actionable for the organization.

Vulnerability and threat analysis is a process of identifying and evaluating the weaknesses or flaws in the organization's assets, processes, or systems that can be exploited or compromised by the potential threats or sources of harm that may affect the organization's objectives or operations. Vulnerability and threat analysis can help the organization to assess and prioritize the risks, and to design and implement appropriate controls or countermeasures to mitigate or prevent the risks, but it is not the best way to identify information systems control deficiencies, because it does not indicate whether the existing information systems controls are adequate and effective, and whether they comply with the organization's policies and standards.

Control remediation planning is a process of selecting and implementing the actions or plans to address or correct the information systems control deficiencies that have been identified, analyzed, and evaluated. Control remediation planning involves choosing one of the following types of control responses: mitigate, transfer, avoid, or accept. Control remediation planning can help the organization to improve and optimize the information systems controls, and to reduce or eliminate the information systems control deficiencies, but it is not the best way to identify information systems control deficiencies, because it is a subsequent or follow-up process that depends on the prior identification of the information systems control deficiencies.

User acceptance testing (UAT) is a process of verifying and validating the functionality and usability of the information systems and resources, using the input and feedback from the end users or customers that interact with the information systems and resources. UAT can help the organization to ensure that the information systems and resources meet the user or customer expectations and requirements, and to identify and resolve any issues or defects that may affect the user or customer satisfaction, but it is not the best way to identify information systems control deficiencies, because it does not focus on the information systems controls, and it may not cover all the relevant or significant information systems control deficiencies that may exist or arise.Reference=

ISACA, CRISC Review Manual, 7th Edition, 2022, pp. 40-41, 47-48, 54-55, 58-59, 62-63

ISACA, CRISC Review Questions, Answers & Explanations Database, 2022, QID 186

CRISC Practice Quiz and Exam Prep


Contribute your Thoughts:

0/2000 characters
Aileen
3 months ago
Surprised that CSA is the top choice, I thought it was more about compliance.
upvoted 0 times
...
Blondell
3 months ago
Vulnerability and threat analysis is key too, though!
upvoted 0 times
...
Frankie
3 months ago
Wait, isn't UAT more about user experience than controls?
upvoted 0 times
...
Chaya
4 months ago
Totally agree, CSA really highlights deficiencies.
upvoted 0 times
...
Art
4 months ago
I think Control self-assessment (CSA) is the best option.
upvoted 0 times
...
Mari
4 months ago
Control remediation planning seems relevant, but I wonder if it’s more about fixing issues rather than identifying them in the first place.
upvoted 0 times
...
Tiffiny
4 months ago
Vulnerability and threat analysis sounds familiar, but I feel like it’s more about identifying risks rather than assessing control deficiencies.
upvoted 0 times
...
Lilli
4 months ago
I'm not entirely sure, but I remember something about user acceptance testing (UAT) being more about functionality than controls.
upvoted 0 times
...
Audra
5 months ago
I think control self-assessment (CSA) might be the best option since it directly involves evaluating the effectiveness of controls.
upvoted 0 times
...
Stephen
5 months ago
This seems straightforward. Vulnerability and threat analysis is the best option because it focuses on identifying potential weaknesses or issues in the information systems controls.
upvoted 0 times
...
Francoise
5 months ago
I'm a little confused by the wording of this question. I'll need to re-read it a few times and maybe jot down some notes to make sure I understand what it's asking before I select an answer.
upvoted 0 times
...
Ula
5 months ago
Okay, I've got this. Control self-assessment (CSA) is the best way to identify control deficiencies because it involves reviewing the controls in place and assessing their effectiveness.
upvoted 0 times
...
Mariann
5 months ago
Hmm, I'm a bit unsure about this one. I'll need to think through the different options carefully to figure out which one is the best way to identify control deficiencies.
upvoted 0 times
...
Ty
5 months ago
This looks like a standard information systems control question. I think the best approach is to focus on the key terms like "control deficiencies" and "identify" to determine the most relevant option.
upvoted 0 times
...
Freeman
11 months ago
That's true, but I still think D) Control self-assessment (CSA) is the best option.
upvoted 0 times
...
Cheryl
11 months ago
But wouldn't C) User acceptance testing (UAT) also help identify control deficiencies?
upvoted 0 times
...
Laila
11 months ago
I think B) Control remediation planning is the most effective.
upvoted 0 times
...
Freeman
11 months ago
I disagree, I believe it's D) Control self-assessment (CSA).
upvoted 0 times
...
Dierdre
12 months ago
User acceptance testing (UAT)? More like 'user acceptance tortured', amirite? But for real, CSA is the way to go.
upvoted 0 times
Elbert
11 months ago
True, but CSA provides a more comprehensive view of control deficiencies.
upvoted 0 times
...
Lindsay
11 months ago
Vulnerability and threat analysis can also be helpful in identifying weaknesses.
upvoted 0 times
...
Oretha
11 months ago
I agree, CSA allows for a more thorough self-assessment of controls.
upvoted 0 times
...
Norah
11 months ago
CSA is definitely the way to go for identifying control deficiencies.
upvoted 0 times
...
...
Cheryl
12 months ago
I think the best way is A) Vulnerability and threat analysis.
upvoted 0 times
...
Benton
12 months ago
Hmm, I'm thinking vulnerability and threat analysis is the real MVP here. You can't fix what you don't know is broken, ya know?
upvoted 0 times
...
Troy
12 months ago
Whoa, control self-assessment (CSA) is definitely the way to go! Gotta love that internal audit feeling, am I right?
upvoted 0 times
Bernardo
11 months ago
Yeah, internal audit is always a fun time.
upvoted 0 times
...
Twila
11 months ago
CSA is a great way to identify control deficiencies.
upvoted 0 times
...
...

Save Cancel