← CISA: audit IT, controls, and resilience
12 / 15 · 60 MIN

Third-party assurance and local responsibility

Relate external reports to services, periods and responsibilities retained by the organization.

The report is not the entire service

An external report can provide useful evidence, but its usefulness depends on its scope and actual conclusion. Identify entity, service, locations, period, criteria and limitations before relying on it. A data-center report does not establish an application tenant’s configuration. In this lesson, the supplier operates infrastructure while the customer manages users and export rules. Audit needs to connect each responsibility with the control objective and suitable evidence. A supplier’s logo does not turn local responsibilities into inherited controls.

Cover the right interval

The audit covers January through September and the external report ends in June. Evidence may support part of the period, while July through September still needs treatment. Request information about changes, incidents and control continuity, evaluating its nature and reliability. A management statement may be relevant without automatically equaling the independent work performed for the earlier period. Do not discard all January-to-June evidence because of the later gap, or claim full-year coverage. State the supported interval and the additional evidence required.

Complementary responsibilities

The service requires the customer to review administrators quarterly. The supplier demonstrates physical protection and platform management, but the local review was not performed. Record the missing responsibility and the risk it addresses. The conclusion should separate supplier control from customer obligation without claiming that a local failure automatically invalidates all external results. Use a matrix containing objective, owner, evidence, period and status. This helps APS and vendor management prevent unowned gaps when a service spans several entities and teams.

Objectivity and factual discussion

Before issuing an observation, confirm facts with the responsible people and consider contradictory evidence. Factual validation does not give management the power to remove significant facts because they are inconvenient. The auditor explains the criterion, observed condition, plausible consequence and evidence limitation. Management proposes actions and owns its risk decisions; the auditor evaluates and follows up without taking over the control they will audit. If involved in design, disclose that involvement and address threats to objectivity under the applicable process. Do not claim independence merely because the job title changed.

Assurance-matrix exercise

Build three rows for a fictional SaaS service: physical security, administrator review and data export. The first has external evidence through June; the second has a local record lacking reviewer attribution; the third changed in August and has not been tested. For each row, state the supported conclusion and next request. The summary should show partial evidence, local responsibility and an out-of-period change without inventing a global “secure” or “insecure” label. A usage decision may still be made, but by the authorized owner with these limitations visible.

IN PRACTICE

An external report covers the platform through June; the September audit keeps the time gap explicit and tests the local administrator review.

Common pitfalls

Confusing an entity with the whole service; extending periods by assumption; treating a statement as equivalent assurance; accepting removal of a fact without new evidence.

Related topics: Inherited controls · Objectivity and communication

Take this idea with you

Reliance on third parties needs matching scope, time and responsibility. The auditor keeps conclusions proportionate to available evidence.

Create account

Reference: Assessing Security and Privacy Controls in Information Systems and Organizations · CISA outline effective August 1, 2024

CISA® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.