Missing Access Logs in Secure Communication Closets
An IS auditor finds that communication closets requiring electronic swipe card access are missing access logs. Which of the following should be done NEXT?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of compensating controls in physical security audits, where candidates often mistakenly investigate incidents or report deficiencies instead of checking for alternative monitoring mechanisms.
This CISA practice question addresses how auditors handle missing physical access logs in secure areas. The explanation confirms that verifying compensating controls like video surveillance is the correct next step.
Option D is frequently chosen because auditors instinctively look for potential breaches (lost/stolen cards), but ISACA prioritizes evaluating existing compensating controls before initiating incident-specific investigations.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When an IS auditor identifies a missing primary control like electronic access logs, the immediate next step is to evaluate compensating controls. Video surveillance serves as a recognized alternative mechanism to monitor and record entry into secure areas, ensuring accountability continues despite the logging gap. ISACA’s audit framework prioritizes verifying existing mitigation measures before escalating findings or initiating reactive investigations.Why the Other Options Are Wrong
Investigating lost or stolen cards (Option D) assumes a breach has already occurred, which jumps ahead of the standard audit procedure of assessing current control effectiveness. Checking for missing equipment (Option C) is also a reactive incident response rather than a systematic control evaluation. Determining management policy approval (Option B) addresses governance compliance but does not resolve the immediate operational monitoring deficit identified during testing.Community Comment Notes
Several learners correctly identified video surveillance as the logical compensating measure, noting that without logs, visual records become essential for tracking unauthorized entries. As RS66 noted, "cameras are the only way to determine if unauthorized personnel accessed the closets." This aligns with ISACA’s emphasis on verifying alternative monitoring mechanisms first. Another participant initially favored assessing stolen cards but later recognized that evaluating the compensating control takes precedence in the audit workflow. The consensus firmly supports Option A as the standard procedural response.Exam Strategy
Always follow the audit sequence: identify the control gap, verify compensating controls, then assess impact. Jumping straight to incident checks or policy reviews bypasses ISACA’s required risk evaluation steps and leads to incorrect sequencing answers.
Frequently Asked Questions
Why not investigate lost or stolen cards first?
Audit methodology requires evaluating compensating controls before launching incident-specific investigations.
Is checking management approval the right next step?
Policy approval is a governance matter; the immediate priority is assessing operational monitoring gaps to determine residual risk.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →