ExamGecko
Question list
Search
Search

Related questions











Question 742 - CISA discussion

Report
Export

A new regulation has been enacted that mandates specific information security practices for the protection of customer data. Which of the following is MOST useful for an IS auditor to review when auditing against the regulation?

A.
Compliance gap analysis
Answers
A.
Compliance gap analysis
B.
Customer data protection roles and responsibilities
Answers
B.
Customer data protection roles and responsibilities
C.
Customer data flow diagram
Answers
C.
Customer data flow diagram
D.
Benchmarking studies of adaptation to the new regulation
Answers
D.
Benchmarking studies of adaptation to the new regulation
Suggested answer: A

Explanation:

A compliance gap analysis is a detailed review of an organization's current state of compliance against a specific regulation or standard.It helps identify the areas and controls that are not meeting the requirements, assess their risk levels, and determine the corrective actions that can be taken to achieve compliance12. A compliance gap analysis is the most useful tool for an IS auditor to review when auditing against a new regulation, as it provides a clear and comprehensive picture of the compliance status, gaps, and remediation plan of the organization.

Reference

1: Information Security Architecture: Gap Assessment and Prioritization - ISACA

2: How to perform Compliance Gap Analysis? - Sprinto

asked 18/09/2024
Bartosz Szewczyk
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first