An external audit firm has been engaged to assess a manufacturer's identity and access management controls. On day one the lead auditor sends the security manager a long list of evidence requests, several of which would require production system changes, and asks for direct read access to the IAM database. The security manager wants the audit to succeed but is also accountable for production stability and data confidentiality. What should the security manager do FIRST?
- AGrant the auditor a temporary privileged account on the IAM database so the evidence requests can be fulfilled without delay.
- BRefer every request to legal so that the audit can only continue once a revised statement of work is signed by both parties.
- CDecline the evidence requests until the auditor narrows the list, on the basis that the volume suggests scope creep beyond what management agreed.
- DReview the requests against the agreed audit scope and evidence protocol, then work with the auditor to provide equivalent evidence through controlled extracts and walkthroughs rather than direct production access. Correct
Why A is wrong: Issuing privileged production access on demand bypasses change control and least privilege, and it also compromises auditor independence by giving them operator capabilities; speed of evidence collection is not a justification for weakening access controls.
Why B is wrong: Legal review of scope changes is reasonable, but routing routine evidence requests through contract renegotiation stalls the audit and is disproportionate when the existing engagement letter already covers evidence access through agreed channels.
Why C is wrong: Outright refusal damages the audit relationship and may itself be reported as a scope limitation. A breadth of requests is normal early in fieldwork; the right response is to manage how evidence is provided, not to block it.
Why D is correct: Facilitating the audit means honouring the engagement while protecting production and confidentiality. Comparing requests to scope, then supplying sanitised extracts, screen-shares, or read-only reporting environments, gives the auditor sufficient evidence without granting standing production access, which is the manager-led risk-balanced response.