712-50 Exam QuestionsBrowse all questions from this exam

712-50 Exam - Question 113


Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.

When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?

Show Answer
Correct Answer: AC

Performing an audit annually is a standard practice in many organizations. It provides a regular and systematic review of security controls to ensure they are still effective in mitigating risks. Annual audits balance thoroughness with practicality, ensuring that controls are regularly reviewed without being overly burdensome on resources.

Discussion

6 comments
Sign in to comment
Pika26Option: C
Mar 22, 2023

Answer is C. Annually.

Otto_Aulicino
Dec 16, 2021

Is this related to the fact that either internal audit or external audit should be doing so, not the CISO? Because to me, it seems like a good idea to audit the controls.

Otto_Aulicino
Dec 16, 2021

Even the next question, #332 is somewhat in line with what I am saying on previous comment. When you implement the control, you check its effectiveness, which could be qualified as an audit.

Perseus_68Option: C
Feb 23, 2024

Unsure, everything should be done at least annually, but is this question about independance. For example the CISO and the team could test and measure a control, should they audit there own implementation or should that come from the audit team that is typically under the CFO. So in that case the CISO should not audit it's own work....

EmporeoOption: C
Mar 23, 2024

controls should be monitored, in that case can be via audit. suggest annually

johndoe69Option: C
Jul 19, 2024

Annually: Performing an audit annually is a standard practice in many organizations. It provides a regular, systematic review of security controls to ensure they are still effective in mitigating risks. This frequency balances thoroughness with practicality, ensuring that controls are regularly reviewed without being overly burdensome on resources.