Certified Information Systems Auditor (CISA) — Question 1418
A third-party consultant is managing the replacement of an accounting system. Which of the following should be the IS auditor's GREATEST concern?
Answer options
- A. The replacement is occurring near year-end reporting.
- B. Data migration is not part of the contracted activities.
- C. Testing was performed by the third-party consultant.
- D. The user department will manage access rights.
Correct answer: B
Explanation
The IS auditor's greatest concern should be that data migration is not included in the contract, as this could lead to data loss or integrity issues. Other options, while important, do not pose as significant a risk to the overall success and security of the accounting system replacement as the lack of a data migration plan. Year-end reporting timing and testing by the consultant, although critical, are manageable with proper oversight.