Certified in Risk and Information Systems Control (CRISC) — Question 1326
Which of the following provides the MOST reliable information to evaluate the current state of control effectiveness?
Answer options
- A. Business impact analysis (BIA)
- B. Control self-assessment (CSA) results
- C. Audit results
- D. Key performance indicators (KPIs)
Correct answer: C
Explanation
Audit results are the most reliable as they provide an objective evaluation of control effectiveness through independent reviews. In contrast, Business impact analysis (BIA) focuses on potential impacts rather than control performance, Control self-assessment (CSA) results may be biased due to self-reporting, and Key performance indicators (KPIs) measure performance metrics but do not directly assess control effectiveness.