Certified Information Systems Auditor (CISA) — Question 233
An IS auditor is preparing a plan for audits to be carried out over a specified period. Which of the following activities should the IS auditor perform FIRST?
Answer options
- A. Allocate audit resources.
- B. Determine the audit universe.
- C. Prioritize risks.
- D. Review prior audit reports.
Correct answer: B
Explanation
The correct answer is B, as determining the audit universe is essential for understanding the scope and boundaries of the audit. Without this foundational knowledge, allocating resources, prioritizing risks, and reviewing past reports would be ineffective. Establishing the audit universe ensures that subsequent planning activities are aligned with the overall audit strategy.