List of questions
Related questions
Question 448 - CISA discussion
An IS auditor identifies that a legacy application to be decommissioned in three months cannot meet the security requirements established by the current policy. What is the BEST way (or the auditor to address this issue?
A.
Recommend the application be patched to meet requirements.
B.
Inform the IT director of the policy noncompliance.
C.
Verify management has approved a policy exception to accept the risk.
D.
Take no action since the application will be decommissioned in three months.
Your answer:
0 comments
Sorted by
Leave a comment first