ExamGecko
Question list
Search
Search

Related questions

Question 211 - CISA discussion

Report
Export

During an IT governance audit, an IS auditor notes that IT policies and procedures are not regularly reviewed and updated. The GREATEST concern to the IS auditor is that policies and procedures might not:

A.
reflect current practices.
Answers
A.
reflect current practices.
B.
include new systems and corresponding process changes.
Answers
B.
include new systems and corresponding process changes.
C.
incorporate changes to relevant laws.
Answers
C.
incorporate changes to relevant laws.
D.
be subject to adequate quality assurance (QA).
Answers
D.
be subject to adequate quality assurance (QA).
Suggested answer: A

Explanation:

The greatest concern for an IS auditor when reviewing IT policies and procedures that are not regularly reviewed and updated is that policies and procedures might not reflect current practices. Policies are documents that define the goals, objectives, and guidelines for an organization's information systems and resources. Procedures are documents that describe the steps, tasks, or activities for implementing or executing policies. Policies and procedures should be regularly reviewed and updated to ensure that they are relevant, accurate, consistent, and effective for the organization's information systems and resources. Policies and procedures that are not regularly reviewed and updated might not reflect current practices, as they might be outdated, obsolete, or incompatible with the current state or needs of the organization's information systems and resources. This can cause confusion, inconsistency, inefficiency, or noncompliance among users or stakeholders who rely on policies and procedures for guidance or direction. Policies and procedures might not include new systems and corresponding process changes is a possible concern for an IS auditor when reviewing IT policies and procedures that are not regularly reviewed and updated, but it is not the greatest one. Policies and procedures might not include new systems and corresponding process changes, as they might be unaware of or unresponsive to the introduction or modification of information systems or resources within the organization. This can cause gaps, overlaps, or conflicts among policies and procedures that affect different information systems or resources.

asked 18/09/2024
Haakon Schjelderup
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first