ExamGecko
Question list
Search
Search

Related questions











Question 394 - CISA discussion

Report
Export

An IS auditor is reviewing the installation of a new server. The IS auditor's PRIMARY objective is to ensure that

A.
security parameters are set in accordance with the manufacturer s standards.
Answers
A.
security parameters are set in accordance with the manufacturer s standards.
B.
a detailed business case was formally approved prior to the purchase.
Answers
B.
a detailed business case was formally approved prior to the purchase.
C.
security parameters are set in accordance with the organization's policies.
Answers
C.
security parameters are set in accordance with the organization's policies.
D.
the procurement project invited lenders from at least three different suppliers.
Answers
D.
the procurement project invited lenders from at least three different suppliers.
Suggested answer: C

Explanation:

The primary objective of an IS auditor when reviewing the installation of a new server is to ensure that security parameters are set in accordance with the organization's policies.Security parameters are settings or options that control the security level and behavior of the server, such as authentication methods, encryption algorithms, access rights, audit logs, firewall rules, or password policies7. The organization's policies are documents that define the security goals, requirements, standards, and guidelines for the organization's information systems. An IS auditor should verify that security parameters are set in accordance with the organization's policies to ensure that the new server complies with the organization's security expectations and regulations. The other options are less important or incorrect because:

A . Security parameters should not be set in accordance with the manufacturer's standards alone, as they may not reflect the organization's specific security needs and environment. The manufacturer's standards are general recommendations or best practices for configuring the server's security parameters based on common scenarios and threats. An IS auditor should compare the manufacturer's standards with the organization's policies and identify any gaps or conflicts that need to be resolved.

B . A detailed business case should have been formally approved prior to the purchase of a new server rather than during its installation. A business case is a document that justifies the need for a new server based on its expected benefits, costs, risks, and alternatives. A business case should be approved by senior management before initiating a project to acquire a new server.

D . The procurement project should have invited tenders from at least three different suppliers before purchasing a new server rather than during its installation. A tender is a formal offer or proposal to provide a product or service at a specified price and quality. Inviting tenders from multiple suppliers helps to ensure a fair and competitive procurement process that can result in the best value for money and quality for the organization.Reference:Server Security - ISACA, [Information Security Policy - ISACA], [Server Hardening - ISACA], [Business Case - ISACA], [Tender - ISACA], [Procurement Management - ISACA]

asked 18/09/2024
CARL COUCH
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first