ExamGecko
Question list
Search
Search

Related questions

Question 15 - CISA discussion

Report
Export

Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?

A.
Perform a business impact analysis (BIA).
Answers
A.
Perform a business impact analysis (BIA).
B.
Determine which databases will be in scope.
Answers
B.
Determine which databases will be in scope.
C.
Identify the most critical database controls.
Answers
C.
Identify the most critical database controls.
D.
Evaluate the types of databases being used
Answers
D.
Evaluate the types of databases being used
Suggested answer: B

Explanation:

The first task that an IS auditor should complete during the preliminary planning phase of a database security review is to determine which databases will be in scope. The scope defines the boundaries and objectives of the audit, as well as the resources, time, and budget required. The IS auditor should identify the databases that are relevant to the audit based on factors such as their criticality, risk, complexity, size, type, location, and ownership. The IS auditor should also consider the regulatory, contractual, and organizational requirements that apply to the databases. By defining the scope clearly and accurately, the IS auditor can ensure that the audit is focused, feasible, and effective.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Christian Weber
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first