Certified Information Systems Auditor (CISA) — Question 233

An IS auditor is preparing a plan for audits to be carried out over a specified period. Which of the following activities should the IS auditor perform FIRST?

Answer options

Correct answer: B

Explanation

The correct answer is B, as determining the audit universe is essential for understanding the scope and boundaries of the audit. Without this foundational knowledge, allocating resources, prioritizing risks, and reviewing past reports would be ineffective. Establishing the audit universe ensures that subsequent planning activities are aligned with the overall audit strategy.