ExamGecko
Question list
Search
Search

Related questions











Question 641 - CISA discussion

Report
Export

Which of the following be of GREATEST concern to an IS auditor reviewing on-site preventive maintenance for an organization's business-critical server hardware?

A.
Preventive maintenance costs exceed the business allocated budget.
Answers
A.
Preventive maintenance costs exceed the business allocated budget.
B.
Preventive maintenance has not been approved by the information system
Answers
B.
Preventive maintenance has not been approved by the information system
C.
Preventive maintenance is outsourced to multiple vendors without requiring nondisclosure agreements (NDAs)
Answers
C.
Preventive maintenance is outsourced to multiple vendors without requiring nondisclosure agreements (NDAs)
D.
The preventive maintenance schedule is based on mean time between failures (MTBF) parameters.
Answers
D.
The preventive maintenance schedule is based on mean time between failures (MTBF) parameters.
Suggested answer: C

Explanation:

The answer C is correct because preventive maintenance is outsourced to multiple vendors without requiring nondisclosure agreements (NDAs) would be of greatest concern to an IS auditor reviewing on-site preventive maintenance for an organization's business-critical server hardware. This is because outsourcing preventive maintenance to multiple vendors without NDAs exposes the organization to the risk of unauthorized access, disclosure, or modification of sensitive data and information stored on the servers. NDAs are legal contracts that bind the vendors to protect the confidentiality and security of the data and information they access or handle during the preventive maintenance. Without NDAs, the vendors may not have any obligation or incentive to safeguard the data and information, and they may misuse, leak, or compromise them for malicious or commercial purposes. This could result in financial losses, reputational damage, legal liabilities, or regulatory penalties for the organization.

The other options are not as concerning as option C. Preventive maintenance costs exceed the business allocated budget (option A) is a financial issue that may affect the profitability or efficiency of the organization, but it does not directly impact the security or availability of the server hardware. Preventive maintenance has not been approved by the information system (option B) is a procedural issue that may indicate a lack of coordination or communication between the IT department and the business units, but it does not necessarily affect the quality or effectiveness of the preventive maintenance. The preventive maintenance schedule is based on mean time between failures (MTBF) parameters (option D) is a technical issue that may influence the frequency or timing of the preventive maintenance, but it does not imply any risk or deficiency in the preventive maintenance itself.

What is a Maintenance Audit?

How to audit your preventative maintenance schedule

5 Step Maintenance Management Program Audit

How do you get effective Preventive Maintenance really?

What is a Planned Preventative Maintenance Audit?

asked 18/09/2024
Vishal Sahare
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first