ExamGecko
Question list
Search
Search

Related questions











Question 897 - CISA discussion

Report
Export

During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is the auditor's BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?

A.
Ensure new employees read and sign acknowledgment of the acceptable use policy.
Answers
A.
Ensure new employees read and sign acknowledgment of the acceptable use policy.
B.
Revise the policy to include security training during onboarding.
Answers
B.
Revise the policy to include security training during onboarding.
C.
Revise the policy to require security training every six months for all employees.
Answers
C.
Revise the policy to require security training every six months for all employees.
D.
Require management of new employees to provide an overview of security awareness.
Answers
D.
Require management of new employees to provide an overview of security awareness.
Suggested answer: B

Explanation:

This directly addresses the gap for new hires, creates a consistent expectation regardless of hiring date, and formalizes the process within organizational policy.

Reference

ISACA CISA Review Manual (Current Edition)- Chapters on Information Security Policies, Training and Awareness

Industry Best Practices for Security Awareness- Emphasize the importance of timely and comprehensive training for new employees.

asked 18/09/2024
Ian Gothard
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first