ExamGecko
Question list
Search
Search

Related questions











Question 251 - CISA discussion

Report
Export

For an organization that has plans to implement web-based trading, it would be MOST important for an IS auditor to verify the organization's information security plan includes:

A.
attributes for system passwords.
Answers
A.
attributes for system passwords.
B.
security training prior to implementation.
Answers
B.
security training prior to implementation.
C.
security requirements for the new application.
Answers
C.
security requirements for the new application.
D.
the firewall configuration for the web server.
Answers
D.
the firewall configuration for the web server.
Suggested answer: C

Explanation:

For an organization that has plans to implement web-based trading, it would be most important for an IS auditor to verify that the organization's information security plan includes security requirements for the new application. Security requirements are statements that define what security features and functions are needed to protect the confidentiality, integrity, and availability of the web-based trading application and its data. Security requirements should be identified and documented during the planning phase of the application development life cycle, before any design or coding activities take place. Attributes for system passwords, security training prior to implementation, and firewall configuration for the web server are also important aspects of information security, but they are not as essential as security requirements for ensuring that the web-based trading application meets its security objectives.

asked 18/09/2024
Aviv Beck
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first