ExamGecko
Question list
Search
Search

Related questions











Question 719 - CISA discussion

Report
Export

Which of the following should be the GREATEST concern to an IS auditor reviewing the information security framework of an organization?

A.
The information security policy has not been updated in the last two years.
Answers
A.
The information security policy has not been updated in the last two years.
B.
Senior management was not involved in the development of the information security policy.
Answers
B.
Senior management was not involved in the development of the information security policy.
C.
A list of critical information assets was not included in the information security policy.
Answers
C.
A list of critical information assets was not included in the information security policy.
D.
The information security policy is not aligned with regulatory requirements.
Answers
D.
The information security policy is not aligned with regulatory requirements.
Suggested answer: D

Explanation:

The effectiveness of an organization's security awareness program can be measured by capturing data on changes in the way people react to threats, such as the ability to recognize and avoid social engineering attacks1.An increase in the number of phishing emails reported by employees indicates that they are more aware of the signs and risks of phishing, and are more likely to take appropriate actions to prevent or mitigate the impact of such attacks23.

Reference

1: The Importance Of Measuring Security Awareness2: Measuring the effectiveness of your security awareness program3: How effective is security awareness training?

asked 18/09/2024
Udara Somachandra
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first