Certified in Risk and Information Systems Control (CRISC) — Question 1162
Which of the following provides the MOST reliable evidence to support conclusions after completing an information systems controls assessment?
Answer options
- A. Information generated by the systems
- B. Confirmation from industry peers
- C. Control environment narratives
- D. Risk and control self-assessment (CSA) reports
Correct answer: A
Explanation
The correct answer is A because information generated by the systems provides direct, objective data that reflects the actual performance and effectiveness of the controls in place. Other options, such as peer confirmation or narratives, may offer insights but lack the empirical evidence necessary for a robust assessment.