ExamGecko
Question list
Search
Search

Related questions











Question 584 - CISA discussion

Report
Export

When evaluating information security governance within an organization, which of the following findings should be of MOST concern to an IS auditor?

A.
The information security department has difficulty filling vacancies
Answers
A.
The information security department has difficulty filling vacancies
B.
An information security governance audit was not conducted within the past year
Answers
B.
An information security governance audit was not conducted within the past year
C.
The data center manager has final sign-off on security projects
Answers
C.
The data center manager has final sign-off on security projects
D.
Information security policies are updated annually
Answers
D.
Information security policies are updated annually
Suggested answer: C

Explanation:

The finding that should be of most concern to an IS auditor when evaluating information security governance within an organization is that the data center manager has final sign-off on security projects. This indicates a lack of segregation of duties and a potential conflict of interest between the operational and security roles. The data center manager may have access to sensitive information or systems that should be protected by security controls, or may influence or override security decisions that are not in the best interest of the organization. This finding also suggests that there is no clear accountability or authority for information security governance at a higher level, such as senior management or board of directors. The other findings are not as concerning as this one, although they may indicate some areas for improvement or monitoring.Reference:

ISACA, CISA Review Manual, 27th Edition, chapter 5, section 5.11

ISACA, IT Governance Using COBIT and Val IT: Student Booklet - 2nd Edition4

asked 18/09/2024
Christopher Harden
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first