ExamGecko
Question list
Search
Search

Related questions

Question 107 - CISA discussion

Report
Export

An IS auditor is evaluating an organization's IT strategy and plans. Which of the following would be of GREATEST concern?

A.
There is not a defined IT security policy.
Answers
A.
There is not a defined IT security policy.
B.
The business strategy meeting minutes are not distributed.
Answers
B.
The business strategy meeting minutes are not distributed.
C.
IT is not engaged in business strategic planning.
Answers
C.
IT is not engaged in business strategic planning.
D.
There is inadequate documentation of IT strategic planning.
Answers
D.
There is inadequate documentation of IT strategic planning.
Suggested answer: C

Explanation:

The greatest concern for an IS auditor when evaluating an organization's IT strategy and plans is that IT is not engaged in business strategic planning, as this indicates a lack of alignment between IT and business objectives, which could result in inefficient and ineffective use of IT resources and capabilities. The absence of a defined IT security policy, the nondistribution of business strategy meeting minutes, and the inadequate documentation of IT strategic planning are also issues that should be addressed by an IS auditor, but they are not as significant as IT's noninvolvement in business strategic planning.Reference:CISA Review Manual (Digital Version), Chapter 3, Section 3.1

asked 18/09/2024
Bogdan Karolic
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first