CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 18


During an IT governance audit, an IS auditor notes that IT policies and procedures are not regularly reviewed and updated. The GREATEST concern to the IS auditor is that policies and procedures might not:

Show Answer
Correct Answer: D

If IT policies and procedures are not regularly reviewed and updated, the greatest concern is that they might not incorporate changes to relevant laws. Compliance with legal and regulatory requirements is critical for any organization. Failing to update policies to reflect changes in the law can result in significant legal penalties, financial losses, and damage to the organization’s reputation. Ensuring policies are updated to comply with legal requirements is therefore paramount.

Discussion

15 comments
Sign in to comment
Victor83516
Mar 6, 2023

Regulations and laws are important external issues that cannot be ignored or avoided. So, I think answer is D.

frisbgOption: A
Nov 24, 2023

Review is conducted to be sure it reflects current practices. Regulation change may change your way of doing your business but law/regulation change may happen in 10 years. I am asking "is it ok for a company not to review their policies and procedures for 10 years?". Answer is is clearly A. If regulation change you will change your way of doing your business, therefor its main purpose.

saado9
Sep 29, 2023

A. reflect current practices.

KAP2HURUFOption: A
Jun 24, 2024

However, the term "GREATEST concern" in the question implies identifying the most critical issue among the options. Reflecting current practices (Option A) is often considered the top priority because it ensures that policies and procedures are not only compliant but also effective in addressing the current state of technology, business operations, and security practices. Keeping policies in line with current practices is fundamental for maintaining a robust IT governance framework.

NDUBU
Nov 1, 2023

A. reflect current practices. Regular review and updates of IT policies and procedures are important to ensure that they align with current practices and standards. Failure to do so can result in policies and procedures becoming outdated, which can create risks and vulnerabilities for the organization. While the other options listed are also important, the primary concern for the IS auditor is to ensure that policies and procedures are up-to-date and accurately reflect the organization's current IT environment.

MAKAYAOption: D
Jul 9, 2023

Answer D is correct

3008Option: A
Dec 6, 2023

While incorporating changes to relevant laws, subjecting policies and procedures to adequate quality assurance (QA), and including new systems and corresponding process changes are all important considerations, they are not the greatest concern to the IS auditor. These issues can also be addressed through regular policy and procedure reviews and updates, ensuring that the policies and procedures reflect current best practices, legal requirements, and organizational needs.

oldmagicOption: D
Dec 7, 2023

D is the correct answer

5b56aaeOption: D
Oct 14, 2024

Laws are the biggest concern

KAP2HURUFOption: D
Nov 30, 2024

D. incorporate changes to relevant laws. The greatest concern for an IS auditor when IT policies and procedures are not regularly reviewed and updated is that they might not incorporate changes to relevant laws and regulations. Compliance with legal and regulatory requirements is critical for any organization, and failure to do so can result in significant legal penalties, financial losses, and damage to the organization's reputation.

sundersam23Option: A
Aug 1, 2024

A is the correct answer

a84nOption: A
Oct 25, 2024

Answer: A

1NaaOption: D
Dec 17, 2024

The outdated IT policies and procedures might not reflect changes in relevant laws and regulations. This poses significant compliance risks, legal liabilities, and potential penalties for the organization. Ensuring policies are updated to incorporate changes to laws is critical for maintaining regulatory compliance and avoiding legal exposure.

SaiRamKumarOption: D
Jan 13, 2025

The legal and regional compliance has major impact

IlationOption: D
Mar 2, 2025

compliance with laws and regulations is always the highest priority in governance audits. Non-compliance risks can lead to financial, legal, and operational consequences, making option D the best choice თამთა შენს გასაგონად ვამბობ!