ExamGecko
Question list
Search
Search

Related questions

Question 996 - CISA discussion

Report
Export

Which of the following is MOST useful when planning to audit an organization's compliance with cybersecurity regulations in foreign countries?

A.
Prioritize the audit to focus on the country presenting the greatest amount of operational risk.
Answers
A.
Prioritize the audit to focus on the country presenting the greatest amount of operational risk.
B.
Follow the cybersecurity regulations of the country with the most stringent requirements.
Answers
B.
Follow the cybersecurity regulations of the country with the most stringent requirements.
C.
Develop a template that standardizes the reporting of findings from each country's audit team
Answers
C.
Develop a template that standardizes the reporting of findings from each country's audit team
D.
Map the different regulatory requirements to the organization's IT governance framework
Answers
D.
Map the different regulatory requirements to the organization's IT governance framework
Suggested answer: D

Explanation:

The most useful thing to do when planning to audit an organization's compliance with cybersecurity regulations in foreign countries is to map the different regulatory requirements to the organization's IT governance framework.This is because an IT governance framework is a roadmap that defines the methods used by an organization to implement, manage and report on IT governance within said organization1.IT governance helps align business and IT strategies using a solid and formal framework2. By mapping the different regulatory requirements to the IT governance framework, the auditor can:

Identify the commonalities and differences among the various cybersecurity regulations that apply to the organization's operations in different countries.

Assess the level of compliance and maturity of the organization's IT governance practices against each regulatory requirement.

Evaluate the risks and gaps associated with non-compliance or partial compliance with any of the regulatory requirements.

Recommend appropriate actions or improvements to enhance the organization's IT governance and cybersecurity posture.

Option D is correct because mapping the different regulatory requirements to the organization's IT governance framework is a systematic and effective way to plan and conduct an audit of compliance with cybersecurity regulations in foreign countries.

asked 18/09/2024
fabio josca
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first