How to Confirm Change Log Completeness in CISA Audits?
An IS auditor evaluating the change management process must select a sample from the change log. What is the BEST way for the auditor to confirm the change log is complete?
Community Votes
80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the difference between completeness and existence assertions, where candidates often confuse forward tracing with backward vouching.
Testing change log completeness requires forward tracing from live system events to documentation. This guide confirms why option B is the correct audit procedure over backward vouching.
Candidates frequently select C because they mistakenly believe sampling from the log verifies accuracy, overlooking that this direction only proves recorded items actually occurred.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Forward tracing from the source data to the audit trail records is the standard method for testing completeness. By selecting a recent change directly from the production environment and verifying its presence in the change log, the auditor demonstrates that the logging mechanism captures events as they happen. This approach aligns with ISACA’s audit doctrine on substantive testing and procedural controls.Why the Other Options Are Wrong
Option C performs backward tracing, which validates existence or accuracy rather than completeness. Option A relies on subjective management claims, which lack independent evidential weight. Option D gathers anecdotal information through inquiry, which is insufficient as standalone audit evidence for process validation.Community Comment Notes
Some learners argue that sampling multiple log entries provides broader coverage, yet this misunderstands the specific assertion being tested. As one commenter noted, checking the most recent system change proves the logging process remains active and timely. Another user emphasized that forward tracing guarantees captured updates, which directly addresses the completeness objective.Exam Strategy
Always identify the specific audit assertion before choosing your testing direction. Map completeness to source-to-record tracing, and reserve record-to-source tracing for existence or accuracy checks.
Frequently Asked Questions
Why does tracing from the log to the system fail here?
That direction tests existence or accuracy, not completeness. Completeness requires proving nothing was omitted by starting with the actual event.
Does checking only the last change prove full log completeness?
It validates that the logging process is active and capturing updates in real time, which satisfies the immediate audit objective for completeness.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →