Isaca CISA Practice Test 14
Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?
The auditor should be most concerned about the information security policy not being approved by the policy owner. This is because the policy owner is the person who has the authority and accountability for ensuring that the policy is implemented and enforced. Without the policy owner's approval, the policy may not reflect the organization's objectives, risks, and compliance requirements. The policy owner is usually a senior executive or a board member who has a stake in the information security governance. The other options are less critical than the policy owner's approval, although they may also indicate some weaknesses in the policy development and maintenance process.Reference:
CISA Review Manual (Digital Version), Chapter 1, Section 1.21
CISA Online Review Course, Domain 5, Module 1, Lesson 12