ExamGecko
Question list
Search
Search

Related questions











Question 675 - CISA discussion

Report
Export

An organization has an acceptable use policy in place, but users do not formally acknowledge the policy. Which of the following is the MOST significant risk from this finding?

A.
Lack of data for measuring compliance
Answers
A.
Lack of data for measuring compliance
B.
Violation of industry standards
Answers
B.
Violation of industry standards
C.
Noncompliance with documentation requirements
Answers
C.
Noncompliance with documentation requirements
D.
Lack of user accountability
Answers
D.
Lack of user accountability
Suggested answer: D

Explanation:

An acceptable use policy (AUP) is a document that defines the rules and guidelines for using an organization's IT resources, such as networks, devices, and software. It aims to protect the organization's assets, security, and productivity. An AUP should be formally acknowledged by users to ensure that they are aware of their responsibilities and obligations when using the IT resources. Without formal acknowledgment, users may not be held accountable for violating the AUP or may claim ignorance of the policy. This can expose the organization to legal, regulatory, reputational, or operational risks. Lack of data for measuring compliance, violation of industry standards, and noncompliance with documentation requirements are also possible risks from not having users acknowledge the AUP, but they are less significant than lack of user accountability.Reference:Workable: Acceptable use policy template,Wikipedia: Acceptable use policy

asked 18/09/2024
Ahmad Mansour
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first