A healthcare provider's annual internal audit reports that the security team is reporting control-effectiveness metrics monthly, but the metrics are drawn from the same monitoring data used to operate the controls and have not been independently corroborated. The audit committee has asked the CISO how to address the finding without doubling the monitoring workload. What is the BEST response?
- AReplace the monthly metrics with an annual third-party control assessment, on the basis that external assurance provides stronger evidence than internal monitoring.
- BDirect the security operations team to dual-key all metric submissions so that two analysts must agree before figures are released to the audit committee.
- CIntroduce periodic independent assessment of a sampled subset of the monitored controls, with the sample and frequency informed by risk and reported alongside the operational metrics. Correct
- DTreat the finding as accepted risk after documenting that the monitoring tooling is configured according to vendor best practice and reviewed by the CISO.
Why A is wrong: Swapping continuous monitoring for an annual external assessment trades timeliness for independence and weakens the organisation's ability to detect control drift between assessments. The audit finding is about corroboration, not about the cadence of monitoring.
Why B is wrong: Dual-keying within the same team improves data integrity but does not introduce independence. The audit finding is that the operators of the control are also the source of the assurance evidence, which a second analyst in the same function does not resolve.
Why C is correct: Layering risk-informed independent assessment on top of operational monitoring directly addresses the corroboration gap without duplicating the full workload. It is the management-led answer that preserves continuous monitoring while satisfying the audit principle that assurance evidence should not be produced solely by the function operating the control.
Why D is wrong: Accepting the finding on the basis of tooling configuration confuses operational hygiene with independent assurance, and risk acceptance without addressing the underlying gap would likely be rejected by the audit committee. It is a defensible-sounding but second-best response.