ExamGecko
Question list
Search
Search

Related questions











Question 437 - CISA discussion

Report
Export

Which of the following is MOST important for an IS auditor to verify when reviewing the use of an outsourcer for disposal of storage media?

A.
The vendor's process appropriately sanitizes the media before disposal
Answers
A.
The vendor's process appropriately sanitizes the media before disposal
B.
The contract includes issuance of a certificate of destruction by the vendor
Answers
B.
The contract includes issuance of a certificate of destruction by the vendor
C.
The vendor has not experienced security incidents in the past.
Answers
C.
The vendor has not experienced security incidents in the past.
D.
The disposal transportation vehicle is fully secure
Answers
D.
The disposal transportation vehicle is fully secure
Suggested answer: A

Explanation:

The most important thing for an IS auditor to verify when reviewing the use of an outsourcer for disposal of storage media is that the vendor's process appropriately sanitizes the media before disposal. As explained in the previous question, storage media may contain sensitive or confidential information that needs to be protected from unauthorized access, disclosure, or misuse. The IS auditor should verify that the vendor has a process that appropriately sanitizes the media before disposal, such as wiping, degaussing, shredding, or incinerating, and that the process is effective and compliant with the organization's policies and standards.The other options are not as important as verifying the vendor's process, because they either do not ensure the security and privacy of the information on the media, or they are secondary to the vendor's process.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.7

asked 18/09/2024
Arslan Ibragimov
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first