Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 822 discussion

Actual exam question from Isaca's CISA
Question #: 822
Topic #: 1
[All CISA Questions]

Which of the following should an IS auditor do FIRST when assessing the level of compliance for an organization in the banking industry?

  • A. Review internal documentation to evaluate adherence to external requirements.
  • B. Confirm there are procedures in place to ensure organizational agreements address legal requirements
  • C. Determine whether the organization has established benchmarks against industry peers for compliance.
  • D. Identify industry-specific requirements that apply to the organization.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Vima234
2 months, 2 weeks ago
Selected Answer: B
B. Confirm there are procedures in place to ensure organizational agreements address legal requirements In highly regulated industries like banking, ensuring that organizational agreements address legal requirements is crucial. By confirming that procedures are in place to address these legal obligations, an IS auditor ensures that the organization has a structured approach to compliance. This step is vital to ascertain that all legal and regulatory requirements are being considered in the organization’s operations.
upvoted 1 times
...
SuperMax
1 year, 1 month ago
Selected Answer: D
D. Identify industry-specific requirements that apply to the organization. Identifying industry-specific requirements is a fundamental step in assessing compliance because it helps the IS auditor understand the specific regulatory and compliance standards that are relevant to the organization's operations in the banking industry. Once these requirements are identified, the auditor can proceed to evaluate how well the organization adheres to them and whether it has established the necessary procedures and documentation to ensure compliance. The other options (A, B, and C) may be relevant to the assessment process, but they typically come after identifying the industry-specific requirements, as they involve evaluating adherence to those requirements and ensuring that organizational procedures align with legal and industry benchmarks.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...