Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?

⚠ Common exam trap

The trap here is treating the organization's own security policy or industry benchmarks as the compliance criteria, when the governing external standard actually defines what must be met.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The requirements of the applicable payment card industry data security standard

A compliance audit measures the subject against authoritative criteria imposed by an external body. Because the payment gateway processes cardholder data, the applicable payment card industry data security standard supplies the mandatory requirements the auditor must test. Internal policies, professional judgment, and peer benchmarks inform the work but cannot establish compliance with the governing standard, so they cannot serve as the primary criteria for this engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The organization's internal information security policy manual and procedures

    Why it's wrong here

    Internal policies are useful for assessing whether management's own controls are consistently applied, but they are not the authoritative external standard for the payment card industry. An entity could have weak internal policies that still satisfy its own manual while breaching the mandated standard. For a compliance audit, the criteria must be the external requirements, not the entity's self-authored rules, so this is a supporting rather than primary basis.

  • ✗

    A benchmark of security controls adopted by similar payment processors in the same region

    Why it's wrong here

    Peer benchmarking can reveal leading practices and highlight gaps, but it is not a compliance criterion. Comparable organizations may be at different maturity levels or may themselves be noncompliant, so their practices cannot establish whether this gateway meets the mandated payment card industry requirements. Benchmarking may supplement the audit, but it cannot replace the authoritative standard as the primary basis for the compliance conclusion.

  • ✓

    The requirements of the applicable payment card industry data security standard

    Why this is correct

    In a compliance audit, the audit criteria are the authoritative requirements imposed on the entity. For a payment gateway handling cardholder data, the applicable payment card industry data security standard defines the mandatory controls the auditor must test against. Using these requirements as the primary basis allows the auditor to conclude whether the organization complies, which is the explicit purpose of this engagement.

  • ✗

    The auditor's professional judgment of what constitutes adequate security for payment gateways

    Why it's wrong here

    Professional judgment guides how the auditor gathers and evaluates evidence, but it cannot substitute for the specific, externally imposed criteria the organization must satisfy. Using personal judgment as the primary basis would make the audit findings subjective and would not establish whether the entity actually complies with the payment card industry requirements governing cardholder data environments, which is the stated objective of this compliance engagement.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.