ExamGecko
Question list
Search
Search

Related questions











Question 525 - CISA discussion

Report
Export

Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?

A.
Security policies are not applicable across all business units
Answers
A.
Security policies are not applicable across all business units
B.
End users are not required to acknowledge security policy training
Answers
B.
End users are not required to acknowledge security policy training
C.
The security policy has not been reviewed within the past year
Answers
C.
The security policy has not been reviewed within the past year
D.
Security policy documents are available on a public domain website
Answers
D.
Security policy documents are available on a public domain website
Suggested answer: D

Explanation:

The auditor should be most concerned about the security policy documents being available on a public domain website. This is because this exposes the organization's security posture and strategy to potential attackers, who can exploit the information to launch targeted attacks or bypass the security controls. The security policy documents should be classified as confidential and protected from unauthorized access or disclosure. The other options are less severe than exposing the security policy documents to the public, although they may also indicate some gaps or weaknesses in the security policy development, implementation, or maintenance process.Reference:

CISA Review Manual (Digital Version), Chapter 5, Section 5.31

CISA Online Review Course, Domain 3, Module 1, Lesson 12

asked 18/09/2024
mahdis khaledi
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first