CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 371


Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?

Show Answer
Correct Answer: AD

Security policy documents being available on a public domain website should be the greatest concern when reviewing an organization's security controls for policy compliance. This exposure represents a significant security risk, as it can provide potential attackers with insights into the organization’s security measures, making it easier for them to find and exploit vulnerabilities. Ensuring that such sensitive documents are protected and only accessible to authorized personnel is crucial for maintaining the integrity and confidentiality of the organization’s security posture.

Discussion

5 comments
Sign in to comment
ChangwhaOption: A
Jul 16, 2023

A. Security policies are not applicable across all business units.

JonnyBGoodOption: A
Jun 1, 2024

No having security policy in some business units is a great concern. Security policies do not necessarily have to be reviewed on a yearly basis.

SibsankarOption: D
Mar 3, 2024

may be D

a84nOption: C
Apr 28, 2024

Answer: C A potential failure in the organization's governance process by not regularly reviewing and updating security policies. This lack of review could result in outdated policies that no longer address current threats or compliance requirements, leading to gaps in security and increased risk exposure Option A: It's more of a structural issue that needs to be addressed in the long term. option D: might not have an immediate impact on policy compliance if the policies themselves are up to date and effectively implemented.

topikalOption: A
Jun 19, 2024

A is a greater concern than C