Valid IIA-CIA-Part2 Dumps shared by ExamDiscuss.com for Helping Passing IIA-CIA-Part2 Exam! ExamDiscuss.com now offer the newest IIA-CIA-Part2 exam dumps, the ExamDiscuss.com IIA-CIA-Part2 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com IIA-CIA-Part2 dumps with Test Engine here:
An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?
Correct Answer: D
When an internal auditor finds that the incidents of noncompliance exceed the organization's acceptable tolerance level, this should be included in the final engagement report. In this case, the 8 out of 90 desks found with sensitive information represent an 8.9% noncompliance rate, which exceeds the organization's tolerance limit of 4%. Reporting this observation in the final engagement report ensures that management is informed and can take necessary corrective actions to address the noncompliance. Reference: IIA Standards: 2410 - Criteria for Communicating IIA Practice Guide: Reporting and Monitoring