Certified Information Systems Auditor (CISA) — Question 129
An IS audit manager was temporarily tasked with supervising a project manager assigned to the organization's payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management experience. What is the BEST course of action?
Answer options
- A. Transfer the assignment to a different audit manager despite lack of IT project management experience
- B. Have a senior IS auditor manage the project with the IS audit manager performing final review
- C. Outsource the audit to independent and qualified resources
- D. Manage the audit since there is no one else with the appropriate experience
Correct answer: C
Explanation
The best choice is to outsource the audit to independent and qualified resources because they can provide an unbiased review and possess specific expertise. The other options either involve inadequate experience or do not leverage the best available resources for a thorough audit.