ExamGecko
Question list
Search
Search

Related questions











Question 338 - CISA discussion

Report
Export

An IS auditor finds that one employee has unauthorized access to confidential data. The IS auditor's BEST recommendation should be to:

A.
reclassify the data to a lower level of confidentiality
Answers
A.
reclassify the data to a lower level of confidentiality
B.
require the business owner to conduct regular access reviews.
Answers
B.
require the business owner to conduct regular access reviews.
C.
implement a strong password schema for users.
Answers
C.
implement a strong password schema for users.
D.
recommend corrective actions to be taken by the security administrator.
Answers
D.
recommend corrective actions to be taken by the security administrator.
Suggested answer: B

Explanation:

The best recommendation for an IS auditor who finds that one employee has unauthorized access to confidential data is to require the business owner to conduct regular access reviews. Access reviews are periodic assessments of user access rights and permissions to ensure that they are appropriate, necessary, and aligned with the business needs and objectives. Access reviews help to identify and remediate any unauthorized, excessive, or obsolete access that could pose a security risk or violate compliance requirements. The business owner is responsible for defining and approving the access requirements for their data and ensuring that they are enforced and monitored.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Jean-Bosco Muganza
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first