ExamGecko
Question list
Search
Search

Related questions











Question 317 - CISA discussion

Report
Export

Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization's information security policy?

A.
IT steering committee minutes
Answers
A.
IT steering committee minutes
B.
Business objectives
Answers
B.
Business objectives
C.
Alignment with the IT tactical plan
Answers
C.
Alignment with the IT tactical plan
D.
Compliance with industry best practice
Answers
D.
Compliance with industry best practice
Suggested answer: B

Explanation:

The most important consideration for an IS auditor when assessing the adequacy of an organization's information security policy is the business objectives. An information security policy is a document that defines the organization's approach to protecting its information assets from internal and external threats.It should align with the organization's mission, vision, values, and goals, and support its business processes and functions1.An information security policy should also be focused on the business needs and requirements of the organization, rather than on technical details or specific solutions2.

The other options are not as important as the business objectives, because they do not directly reflect the organization's purpose and direction. IT steering committee minutes are records of the discussions and decisions made by a group of senior executives who oversee the IT strategy and governance of the organization.They may provide some insights into the information security policy, but they are not sufficient to evaluate its adequacy3. Alignment with the IT tactical plan is a measure of how well the information security policy supports the short-term actions and projects that implement the IT strategy.However, the IT tactical plan itself should be aligned with the business objectives, and not vice versa4. Compliance with industry best practice is a desirable quality of an information security policy, but it is not a guarantee of its effectiveness or suitability for the organization. Industry best practices are general guidelines or recommendations that may not apply to every organization or situation. An information security policy should be customized and tailored to the specific context and needs of the organization.Reference:

The 12 Elements of an Information Security Policy | Exabeam1

11 Key Elements of an Information Security Policy | Egnyte2

What is an IT steering committee?Definition, roles & responsibilities ...3

What is IT Strategy?Definition, Components & Best Practices | BMC ...4

IT Security Policy: Key Components & Best Practices for Every Business

asked 18/09/2024
Emanuele Facchini
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first