ExamGecko
Question list
Search
Search

Related questions











Question 714 - CISA discussion

Report
Export

An IS auditor discovers from patch logs that some in-scope systems are not compliant with the regular patching schedule. What should the auditor do NEXT?

A.
Interview IT management to clarify the current procedure.
Answers
A.
Interview IT management to clarify the current procedure.
B.
Report this finding to senior management.
Answers
B.
Report this finding to senior management.
C.
Review the organization's patch management policy.
Answers
C.
Review the organization's patch management policy.
D.
Request a plan of action to be established as a follow-up item.
Answers
D.
Request a plan of action to be established as a follow-up item.
Suggested answer: C

Explanation:

The IS auditor should review the organization's patch management policy to determine the expected frequency and scope of patching, as well as the roles and responsibilities of the patch management team.This will help the auditor assess the severity and impact of the non-compliance, and identify the root cause and possible remediation actions12.

Reference

1: How to Create a Patch Management Policy: Complete Guide2: Free Patch Management Policy Template (+Examples)

asked 18/09/2024
Pablo Galilea
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first