ExamGecko
Question list
Search
Search

Related questions











Question 436 - CISA discussion

Report
Export

An IS auditor notes that not all security tests were completed for an online sales system recently promoted to production. Which of the following is the auditor's BEST course of action?

A.
Determine exposure to the business
Answers
A.
Determine exposure to the business
B.
Adjust future testing activities accordingly
Answers
B.
Adjust future testing activities accordingly
C.
Increase monitoring for security incidents
Answers
C.
Increase monitoring for security incidents
D.
Hire a third party to perform security testing
Answers
D.
Hire a third party to perform security testing
Suggested answer: A

Explanation:

The IS auditor's best course of action when reviewing the use of an outsourcer for disposal of storage media is to determine exposure to the business. Storage media, such as hard disks, tapes, flash drives, or CDs, may contain sensitive or confidential information that needs to be protected from unauthorized access, disclosure, or misuse. The IS auditor should verify that the outsourcer has a process that appropriately sanitizes the media before disposal, such as wiping, degaussing, shredding, or incinerating, and that the process is effective and compliant with the organization's policies and standards. The IS auditor should also assess the potential impact and risk to the business if the storage media is not properly sanitized or disposed of, such as data breaches, reputational damage, legal or regulatory penalties, or loss of competitive advantage.The other options are not the best course of action, because they either do not address the root cause of the problem, or they are reactive rather than proactive measures.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.7

asked 18/09/2024
Peter Klaffehn
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first