ExamGecko
Question list
Search
Search

Related questions











Question 255 - CISA discussion

Report
Export

What is the Most critical finding when reviewing an organization's information security management?

A.
No dedicated security officer
Answers
A.
No dedicated security officer
B.
No official charier for the information security management system
Answers
B.
No official charier for the information security management system
C.
No periodic assessments to identify threats and vulnerabilities
Answers
C.
No periodic assessments to identify threats and vulnerabilities
D.
No employee awareness training and education program
Answers
D.
No employee awareness training and education program
Suggested answer: C

Explanation:

The most critical finding when reviewing an organization's information security management is no periodic assessments to identify threats and vulnerabilities. Periodic assessments are essential for ensuring that the organization's information security policies, procedures, standards, and controls are aligned with the current and emerging risks and threats that may affect its information assets. Without periodic assessments, the organization may not be aware of its actual security posture, gaps, or weaknesses, and may not be able to take appropriate measures to mitigate or prevent potential security incidents. No dedicated security officer, no official charter for the information security management system, and no employee awareness training and education program are also findings that may indicate some deficiencies in the organization's information security management, but they are not as critical as no periodic assessments to identify threats and vulnerabilities.Reference:ISACA CISA Review Manual 27th Edition, page 343.

asked 18/09/2024
Carlos Almeida Fernandes
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first