Which of the following is MOST important for an IS auditor to review when determining whether IT investments are providing value to tie business?
The answer B is correct because the most important thing for an IS auditor to review when determining whether IT investments are providing value to the business is the business strategy. The business strategy is the plan or direction that guides the organization's decisions and actions to achieve its goals and objectives. The business strategy defines the organization's vision, mission, values, competitive advantage, target market, value proposition, and key performance indicators (KPIs).
IT investments are the expenditures or costs incurred by the organization to acquire, develop, maintain, or improve its IT assets, such as hardware, software, network, data, or services. IT investments can help the organization to support its business processes, operations, functions, and capabilities. IT investments can also help the organization to create or enhance its products, services, or solutions for its customers or stakeholders.
To determine whether IT investments are providing value to the business, an IS auditor needs to review how well the IT investments align with and contribute to the business strategy. Alignment means that the IT investments are consistent and compatible with the business strategy, and that they support and enable the achievement of the strategic goals and objectives. Contribution meansthat the IT investments are effective and efficient in delivering the expected outcomes and benefits for the business, and that they generate a positive return on investment (ROI) or value for money.
An IS auditor can use various methods or frameworks to review the alignment and contribution of IT investments to the business strategy, such as:
Balanced scorecard: A balanced scorecard is a tool that measures and monitors the performance of an organization across four perspectives: financial, customer, internal process, and learning and growth. A balanced scorecard can help an IS auditor to evaluate how well the IT investments support and improve each perspective of the organization's performance, and how they link to the organization's vision and strategy.
Value chain analysis: A value chain analysis is a tool that identifies and analyzes the primary and support activities that add value to an organization's products or services. A value chain analysis can help an IS auditor to assess how well the IT investments enhance or optimize each activity of the value chain, and how they create or sustain a competitive advantage for the organization.
Business case analysis: A business case analysis is a tool that evaluates the feasibility, viability, and desirability of a proposed project or initiative. A business case analysis can help an IS auditor to examine how well the IT investments address a business problem or opportunity, how they deliver the expected benefits and outcomes for the stakeholders, and how they compare with alternative options or solutions.
The other options are not as important as option B. Return on investment (ROI) (option A) is a metric that measures the profitability or efficiency of an investment by comparing its benefits or returns with its costs or expenses. ROI can help an IS auditor to quantify the value of IT investments for the business, but it does not capture all aspects of value, such as quality, satisfaction, or impact. ROI also depends on how well the IT investments align with the business strategy in the first place. Business cases (option C) are documents that justify and support a proposed project or initiative by describing its objectives, scope, benefits, costs, risks, and alternatives. Business cases can help an IS auditor to understand the rationale and expectations for IT investments, but they do not guarantee that the IT investments will actually deliver the desired value for the business. Business cases also need to be aligned with the business strategy to ensure their relevance and validity. Total cost of ownership (TCO) (option D) is a metric that measures the total costs incurred by an organization to acquire, operate, maintain, and dispose of an IT asset over its life cycle. TCO can help an IS auditor to estimate the financial impact of IT investments for the business, but it does not reflect the benefits or outcomes of IT investments, nor does it indicate how well the IT investments support or enable the business strategy.
IT Strategy: Aligning IT and Business Strategy
How To Measure The Value Of Your Technology Investments
IT Investment Management: A Framework for Assessing ... - GAO
How To Align Your Technology Investments With Your Business Strategy
A web application is developed in-house by an organization. Which of the following would provide the BEST evidence to an IS auditor that the application is secure from external attack?
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?
A web-based CRM system that is directly accessed by customers via the Internet should be hosted in a secure and isolated environment to protect it from external threats and unauthorized access.A web-based CRM system should also be reliable, trusted, and backedup regularly1.
Hosting the system on an external third-party service provider's servers (A) or a hybrid-cloud platform managed by a service provider (B) may not be a concern for the auditor if the service provider has adequate security measures and service level agreements in place.The auditor should verify the security controls and contractual terms of the service provider before trusting them with the CRM data23.
Hosting the system within a demilitarized zone (DMZ) of a corporate network is a common practice to provide an extra layer of security to the CRM system from untrusted networks, such as the Internet.A DMZ is a perimeter network that isolates the CRM system from the internal network and filters the incoming traffic from the external network using a security gateway4567.
Hosting the system within an internal segment of a corporate network (D) is a concern for the auditor because it exposes the CRM system and the internal network to potential attacks from the Internet. The CRM system should not be directly accessible from the Internet without a DMZ or a firewall to protect it.This could compromise the confidentiality, integrity, and availability of the CRM data and the internal network78.
Which of the following BEST facilitates the legal process in the event of an incident?
The best way to facilitate the legal process in the event of an incident is to preserve the chain of custody of the evidence. The chain of custody is a record of who handled, accessed, or modified the evidence, when, where, how, and why. The chain of custody helps to ensure the integrity, authenticity, and admissibility of the evidence in a court of law. The chain of custody also helps to prevent tampering, alteration, or loss of evidence that could compromise the investigation or the prosecution.Reference:
CISAReview Manual (Digital Version)
CISA Questions, Answers and Explanations Database
Which of the following is MOST important for an IS auditor to assess during a post-implementation review of a newly modified IT application developed in-house?
A post-implementation review (PIR) of a newly modified IT application focuses on ensuring that the system meets business and security requirements effectively. The sufficiency of implemented controls (A) is the most critical aspect because it ensures that security, operational, and compliance controls are functioning correctly. These controls include access controls, data integrity checks, and audit logs to prevent unauthorized access, data corruption, or security breaches.
Other options:
Resource management plan (B) is important for project management but is not the primary concern for an IS auditor in a post-implementation review.
Updates required for end-user manuals (C) are necessary for usability but do not impact the security or operational integrity of the system.
Rollback plans for changes (D) are important for change management but are typically assessed before deployment, not in a PIR.
Kimberly Reed
8 days agoDennis Williams
30 days agoOlivia Phillips
1 month agoNancy Miller
2 months agoAngela Williams
2 months agoRobert Cooper
3 months agoRachel Roberts
3 months agoOlivia Collins
4 months agoGeorge Adams
4 months agoLinda Scott
5 months agoDonald Rivera
5 months agoStephen Ramirez
4 months agoJames Rivera
4 months agoTiffany Allen
4 months agoCrystal Thompson
5 months agoSuzan
5 months agoWilliam
6 months agoTyisha
6 months agoBarabara
6 months agoBrett
6 months agoLindsey
7 months agoCorazon
7 months agoChantell
7 months agoBlossom
7 months agoEllen
8 months agoWilson
8 months agoMaile
8 months agoAja
8 months agoGearldine
9 months agoKaycee
9 months agoKizzy
9 months agoJose
9 months agoAlbert
10 months agoShakira
10 months agoMelynda
10 months agoAretha
10 months agoFrancis
11 months agoAshley
11 months agoZana
11 months agoBasilia
11 months agoDiego
12 months agoSilva
12 months agoVelda
1 year agoJenifer
1 year agoNettie
1 year agoCarey
1 year agoMike
1 year agoNan
1 year agoHelene
2 years agoStephane
2 years agoNu
2 years agoDanilo
2 years agoCathrine
2 years agoDanilo
2 years agoTamala
2 years agoRoyce
2 years agoJade
2 years agoJennie
2 years agoEric
2 years agoTheron
2 years agoJaime
2 years agoLorenza
2 years agoStaci
2 years agoMoon
2 years agoFelicidad
2 years agoSheridan
2 years agoAmmie
2 years agoTijuana
2 years agoMireya
2 years agoDoug
2 years agoSamuel
2 years agoStefany
2 years agoSharee
2 years ago