ExamGecko
Question list
Search
Search

Related questions

Question 289 - CISA discussion

Report
Export

Which of the following should an IS auditor review FIRST when planning a customer data privacy audit?

A.
Legal and compliance requirements
Answers
A.
Legal and compliance requirements
B.
Customer agreements
Answers
B.
Customer agreements
C.
Data classification
Answers
C.
Data classification
D.
Organizational policies and procedures
Answers
D.
Organizational policies and procedures
Suggested answer: D

Explanation:

The organizational policies and procedures are the first source of guidance for an IS auditor when planning a customer data privacy audit. They provide the framework and objectives for ensuring compliance with legal and regulatory requirements, customer agreements and data classification. The IS auditor should review them first to understand the scope, roles and responsibilities, standards and controls related to customer data privacy in the organization.The other options are also important, but they are secondary sources of information that should be reviewed after the organizational policies and procedures.Reference:CISA Review Manual (Digital Version)1, Chapter 2: Governance and Management of Information Technology, Section 2.5: Privacy Principles and Policies.

asked 18/09/2024
Patricia Vontitte
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first