A bank's web-hosting provider has just completed an internal IT security audit and provides only a summary of the findings to the bank's auditor. Which of the following should be the bank's GREATEST concern?
A.
The audit scope may not have addressed critical areas.
B.
The audit procedures are not provided to the bank.
C.
The bank's auditors are not independent of the service provider.
D.
The audit may be duplicative of the bank's internal audit procedures
As a Bank: Your greatest concern should indeed be whether the audit scope covered all critical areas (Option A). This impacts your ability to manage risks and ensure that all necessary security controls are in place.
As an Audit Function: Independence of the auditors (Option C) is paramount. It ensures that the audit findings are objective, reliable, and comply with professional standards.
Why is the answer not C? I think the question is not about content of the audit but who they submitted the audits findings to. So the bank greatest concern here is the auditors not independent of the bank
The bank's greatest concern in this scenario is the possibility that the audit scope may not have addressed critical areas (Option A). The summary provided by the web-hosting provider may not provide the bank with sufficient information to determine whether the audit scope was adequate and whether all critical areas were assessed
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Zephaniah
Highly Voted 2 years, 2 months agoPurpleParrot
Most Recent 3 months, 1 week agoblues_lee
9 months, 3 weeks agoRachy
10 months, 1 week agoanaluisamoreira
4 months, 3 weeks ago3008
1 year, 3 months agoDeeplaxmi
2 years, 2 months agoMunaM
2 years, 2 months ago