ExamGecko
Question list
Search
Search

Related questions











Question 614 - CISA discussion

Report
Export

Which of the following is the MOST important outcome of an information security program?

A.
Operating system weaknesses are more easily identified.
Answers
A.
Operating system weaknesses are more easily identified.
B.
Emerging security technologies are better understood and accepted.
Answers
B.
Emerging security technologies are better understood and accepted.
C.
The cost to mitigate information security risk is reduced.
Answers
C.
The cost to mitigate information security risk is reduced.
D.
Organizational awareness of security responsibilities is improved.
Answers
D.
Organizational awareness of security responsibilities is improved.
Suggested answer: D

Explanation:

The most important outcome of an information security program is to improve the organizational awareness of security responsibilities, as this will foster a culture of security and ensure that all stakeholders are aware of their roles and obligations in protecting the information assets of the organization. An information security program should also aim to achieve other outcomes, such as identifying operating system weaknesses, understanding and accepting emerging security technologies, and reducing the cost to mitigate information security risk, but these are not as important as improving the awareness of security responsibilities, which is the foundation of any effective information security program.*Reference: According to the ISACA IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 2402 Planning, ''The IS audit and assurance professional should identify and assess risk relevant to the area under review.''1One of the risk factors to consider is ''the level of awareness of management and staff regarding IT risk management''1.According to the ISACA IT Audit and Assurance Guideline G13 Information Security Management, ''The objective of an information security management audit/assurance review is to provide management with an independent assessment relating to the effectiveness of information security management within the enterprise.'' The guideline also states that ''the audit/assurance professional should evaluate whether there is an appropriate level of awareness throughout the enterprise regarding information security policies, standards, procedures and guidelines.'' According to a web search result from Microsoft Security, ''Information security programs need to: ... Support the execution of decisions.''2One of the ways to support the execution of decisions is to ensure that everyone in the organization understands their security responsibilities and follows the security policies and procedures.

asked 18/09/2024
Malik Adeel Imtiaz
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first