ExamGecko
Question list
Search
Search

Related questions

Question 170 - CISA discussion

Report
Export

An IS auditor concludes that an organization has a quality security policy. Which of the following is MOST important to determine next? The policy must be:

A.
well understood by all employees.
Answers
A.
well understood by all employees.
B.
based on industry standards.
Answers
B.
based on industry standards.
C.
developed by process owners.
Answers
C.
developed by process owners.
D.
updated frequently.
Answers
D.
updated frequently.
Suggested answer: A

Explanation:

The most important thing to determine next after concluding that an organization has a quality security policy is whether the policy is well understood by all employees. A security policy is a document that defines the objectives, scope, roles, responsibilities, and rules for information security within an organization. A quality security policy is one that is clear, concise, consistent, comprehensive, and aligned with business goals and requirements. However, a quality security policy is useless if it is not well understood by all employees who are expected to comply with it. Therefore, the IS auditor should assess the level of awareness and understanding of the security policy among employees and identify any gaps or issues that need to be addressed. The other options are not as important as ensuring that the security policy is well understood by all employees, as they do not directly affect the implementation and effectiveness of the security policy.Reference:CISA Review Manual, 27th Edition, page 317

asked 18/09/2024
Roger Wehrli
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first