ExamGecko
Question list
Search
Search

Related questions











Question 569 - CISA discussion

Report
Export

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

A.
Consultation with security staff
Answers
A.
Consultation with security staff
B.
Inclusion of mission and objectives
Answers
B.
Inclusion of mission and objectives
C.
Compliance with relevant regulations
Answers
C.
Compliance with relevant regulations
D.
Alignment with an information security framework
Answers
D.
Alignment with an information security framework
Suggested answer: D

Explanation:

Information security policies and procedures are the foundation of an organization's information security program. They define the roles, responsibilities, rules, and standards for protecting information assets from unauthorized access, use, disclosure, modification, or destruction. The most important factor when developing information security policies and procedures is to align them with an information security framework that provides a comprehensive and consistent approach to managing information security risks. An information security framework can also help ensure compliance with relevant regulations, inclusion of mission and objectives, and consultation with security staff. However, these factors are secondary to alignment with an information security framework.Reference:CISA Certification | Certified Information Systems Auditor | ISACA,CISA Review Manual (Digital Version)

asked 18/09/2024
Solomon Waya
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first