CISA Information System Auditing Process Practice Question
An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?
⚠ Common exam trap
The trap here is treating the organization's own security policy or industry benchmarks as the compliance criteria, when the governing external standard actually defines what must be met.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The requirements of the applicable payment card industry data security standard
A compliance audit measures the subject against authoritative criteria imposed by an external body. Because the payment gateway processes cardholder data, the applicable payment card industry data security standard supplies the mandatory requirements the auditor must test. Internal policies, professional judgment, and peer benchmarks inform the work but cannot establish compliance with the governing standard, so they cannot serve as the primary criteria for this engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The organization's internal information security policy manual and procedures
Why it's wrong here
Internal policies are useful for assessing whether management's own controls are consistently applied, but they are not the authoritative external standard for the payment card industry. An entity could have weak internal policies that still satisfy its own manual while breaching the mandated standard. For a compliance audit, the criteria must be the external requirements, not the entity's self-authored rules, so this is a supporting rather than primary basis.
- ✗
A benchmark of security controls adopted by similar payment processors in the same region
Why it's wrong here
Peer benchmarking can reveal leading practices and highlight gaps, but it is not a compliance criterion. Comparable organizations may be at different maturity levels or may themselves be noncompliant, so their practices cannot establish whether this gateway meets the mandated payment card industry requirements. Benchmarking may supplement the audit, but it cannot replace the authoritative standard as the primary basis for the compliance conclusion.
- ✓
The requirements of the applicable payment card industry data security standard
Why this is correct
In a compliance audit, the audit criteria are the authoritative requirements imposed on the entity. For a payment gateway handling cardholder data, the applicable payment card industry data security standard defines the mandatory controls the auditor must test against. Using these requirements as the primary basis allows the auditor to conclude whether the organization complies, which is the explicit purpose of this engagement.
- ✗
The auditor's professional judgment of what constitutes adequate security for payment gateways
Why it's wrong here
Professional judgment guides how the auditor gathers and evaluates evidence, but it cannot substitute for the specific, externally imposed criteria the organization must satisfy. Using personal judgment as the primary basis would make the audit findings subjective and would not establish whether the entity actually complies with the payment card industry requirements governing cardholder data environments, which is the stated objective of this compliance engagement.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.