A web application is developed in-house by an organization. Which of the following would provide the BEST evidence to an IS auditor that the application is secure from external attack?
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?
A web-based CRM system that is directly accessed by customers via the Internet should be hosted in a secure and isolated environment to protect it from external threats and unauthorized access.A web-based CRM system should also be reliable, trusted, and backedup regularly1.
Hosting the system on an external third-party service provider's servers (A) or a hybrid-cloud platform managed by a service provider (B) may not be a concern for the auditor if the service provider has adequate security measures and service level agreements in place.The auditor should verify the security controls and contractual terms of the service provider before trusting them with the CRM data23.
Hosting the system within a demilitarized zone (DMZ) of a corporate network is a common practice to provide an extra layer of security to the CRM system from untrusted networks, such as the Internet.A DMZ is a perimeter network that isolates the CRM system from the internal network and filters the incoming traffic from the external network using a security gateway4567.
Hosting the system within an internal segment of a corporate network (D) is a concern for the auditor because it exposes the CRM system and the internal network to potential attacks from the Internet. The CRM system should not be directly accessible from the Internet without a DMZ or a firewall to protect it.This could compromise the confidentiality, integrity, and availability of the CRM data and the internal network78.
Which of the following BEST facilitates the legal process in the event of an incident?
The best way to facilitate the legal process in the event of an incident is to preserve the chain of custody of the evidence. The chain of custody is a record of who handled, accessed, or modified the evidence, when, where, how, and why. The chain of custody helps to ensure the integrity, authenticity, and admissibility of the evidence in a court of law. The chain of custody also helps to prevent tampering, alteration, or loss of evidence that could compromise the investigation or the prosecution.Reference:
CISAReview Manual (Digital Version)
CISA Questions, Answers and Explanations Database
Which of the following is MOST important for an IS auditor to assess during a post-implementation review of a newly modified IT application developed in-house?
A post-implementation review (PIR) of a newly modified IT application focuses on ensuring that the system meets business and security requirements effectively. The sufficiency of implemented controls (A) is the most critical aspect because it ensures that security, operational, and compliance controls are functioning correctly. These controls include access controls, data integrity checks, and audit logs to prevent unauthorized access, data corruption, or security breaches.
Other options:
Resource management plan (B) is important for project management but is not the primary concern for an IS auditor in a post-implementation review.
Updates required for end-user manuals (C) are necessary for usability but do not impact the security or operational integrity of the system.
Rollback plans for changes (D) are important for change management but are typically assessed before deployment, not in a PIR.
In an annual audit cycle, the audit of an organization's IT department resulted in many findings. Which of the following would be the MOST important consideration when planning the next audit?
The most important consideration when planning the next audit after many findings is to follow up on the status of all recommendations, as this will ensure that the audit findings are addressed in a timely and effective manner, and that the root causes of the issues are resolved12.Following up on the status of all recommendations will also help to assess the progress and performance of the IT department, and to identify any new or emerging risks or challenges34.
References
1: What to consider when resolving internal audit findings32: A brief guide to follow up43: Guidance on auditing planning for Internal Audit24: Corrective Action Plan (CAP): How to Manage Audit Findings1
Nancy Miller
13 days agoAngela Williams
22 days agoRobert Cooper
1 month agoRachel Roberts
2 months agoOlivia Collins
2 months agoGeorge Adams
3 months agoLinda Scott
3 months agoDonald Rivera
3 months agoStephen Ramirez
3 months agoJames Rivera
3 months agoTiffany Allen
2 months agoCrystal Thompson
3 months agoSuzan
4 months agoWilliam
4 months agoTyisha
4 months agoBarabara
5 months agoBrett
5 months agoLindsey
5 months agoCorazon
5 months agoChantell
6 months agoBlossom
6 months agoEllen
6 months agoWilson
6 months agoMaile
7 months agoAja
7 months agoGearldine
7 months agoKaycee
7 months agoKizzy
8 months agoJose
8 months agoAlbert
8 months agoShakira
8 months agoMelynda
9 months agoAretha
9 months agoFrancis
9 months agoAshley
9 months agoZana
10 months agoBasilia
10 months agoDiego
10 months agoSilva
10 months agoVelda
11 months agoJenifer
11 months agoNettie
1 year agoCarey
1 year agoMike
1 year agoNan
1 year agoHelene
1 year agoStephane
1 year agoNu
2 years agoDanilo
2 years agoCathrine
2 years agoDanilo
2 years agoTamala
2 years agoRoyce
2 years agoJade
2 years agoJennie
2 years agoEric
2 years agoTheron
2 years agoJaime
2 years agoLorenza
2 years agoStaci
2 years agoMoon
2 years agoFelicidad
2 years agoSheridan
2 years agoAmmie
2 years agoTijuana
2 years agoMireya
2 years agoDoug
2 years agoSamuel
2 years agoStefany
2 years agoSharee
2 years ago