CISA Certified Information Systems Auditor – Question0697

Following an acquisition, it was decided that legacy applications subject to compliance requirements will continue to be used until they can be phased out. The IS auditor needs to determine where there are control redundancies and where gaps may exist. Which of the following activities would be MOST helpful in making this determination?

A.
Control self-assessments
B. Risk assessment
C. Control testing
D. Control mapping

Correct Answer: A