ExamGecko
Question list
Search
Search

Related questions

Question 222 - CISA discussion

Report
Export

Which of the following is the PRIMARY role of the IS auditor m an organization's information classification process?

A.
Securing information assets in accordance with the classification assigned
Answers
A.
Securing information assets in accordance with the classification assigned
B.
Validating that assets are protected according to assigned classification
Answers
B.
Validating that assets are protected according to assigned classification
C.
Ensuring classification levels align with regulatory guidelines
Answers
C.
Ensuring classification levels align with regulatory guidelines
D.
Defining classification levels for information assets within the organization
Answers
D.
Defining classification levels for information assets within the organization
Suggested answer: B

Explanation:

Validating that assets are protected according to assigned classification is the primary role of the IS auditor in an organization's information classification process. An IS auditor should evaluate whether the information security controls are adequate and effective in safeguarding the information assets based on their classification levels. The other options are not the primary role of the IS auditor, but rather the responsibilities of the information owners, custodians, or security managers.Reference:

CISA Review Manual (Digital Version), Chapter 6, Section 6.2.31

CISA Review Questions, Answers & Explanations Database, Question ID 206

asked 18/09/2024
Peter Lilley
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first