CISA Certified Information Systems Auditor – Question2278

What should an IS auditor do if he or she observes that project-approval procedures do not exist?

A.
Advise senior management to invest in project-management training for the staff
B. Create project-approval procedures for future project implementations
C. Assign project leaders
D. Recommend to management that formal approval procedures be adopted and documented

Correct Answer: D

Explanation:

Explanation:
If an IS auditor observes that project-approval procedures do not exist, the IS auditor should recommend to management that formal approval procedures be adopted and documented.