CISA Certified Information Systems Auditor – Question0165

A previously agreed-upon recommendation was not implemented because the auditee no longer agrees with the original findings. The IS auditor’s FIRST course of action should be to:

A.
exclude the finding in the follow-up audit report.
B. escalate the disagreement to the audit committee.
C. assess the reason for the disagreement.
D. require implementation of the original recommendation.

Correct Answer: C