🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor18 / 148
Question 18 of 148

An IS auditor has completed fieldwork on a review of the organization's identity and access management processes. Several control weaknesses were identified, some highly technical (e.g., misconfigured LDAP bind accounts) and some governance-related (e.g., no periodic access recertification). The auditor is preparing to communicate the results to the audit committee, which is composed primarily of non-technical board members. What should the auditor do FIRST when structuring the report for this audience?

Reviewed for accuracy · Report an issueNext question