ExamGecko
Question list
Search
Search

Related questions











Question 626 - CISA discussion

Report
Export

Which of the following should an IS auditor recommend be done FIRST when an organization is made aware of a new regulation that is likely to impact IT security requirements?

A.
Update security policies based on the new regulation.
Answers
A.
Update security policies based on the new regulation.
B.
Determine which systems and IT-related processes may be impacted.
Answers
B.
Determine which systems and IT-related processes may be impacted.
C.
Evaluate how security awareness and training content may be impacted.
Answers
C.
Evaluate how security awareness and training content may be impacted.
D.
Review the design and effectiveness of existing IT controls.
Answers
D.
Review the design and effectiveness of existing IT controls.
Suggested answer: B

Explanation:

The first thing that an IS auditor should recommend when an organization is made aware of a new regulation that is likely to impact IT security requirements is to determine which systems and IT-related processes may be impacted. This is because the impact assessment is a crucial step to understand the scope and magnitude of the changes that the new regulation may entail, as well as the potential risks and gaps that need to be addressed.The impact assessment can help the organization to prioritize and plan the necessary actions and resources to comply with the new regulation in a timely and effective manner12.

Updating security policies based on the new regulation is not the first thing to do, because it requires a clear understanding of the impact and implications of the new regulation, which can only be obtained after conducting an impact assessment.Updating security policies without an impact assessment may result in incomplete, inconsistent, or ineffective policies that may not meet the regulatory requirements or the organizational needs12.

Evaluating how security awareness and training content may be impacted is not the first thing to do, because it is a secondary or supporting activity that depends on the results of the impact assessment and the policy updates.Evaluating security awareness and training content without an impact assessment or policy updates may result in inaccurate, outdated, or irrelevant content that may not reflect the regulatory requirements or the organizational expectations34.

Reviewing the design and effectiveness of existing IT controls is not the first thing to do, because it is a monitoring or assurance activity that follows the implementation of the changes based on the impact assessment and the policy updates.Reviewing IT controls without an impact assessment or policy updates may result in misleading, incomplete, or invalid findings that may not capture the regulatory requirements or the organizational performance

asked 18/09/2024
Nghia To Duc
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first