CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 281


Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended that both organizations agree to and document an acceptable use policy for the equipment. What type of control has been recommended?

Show Answer
Correct Answer: D

The recommended control is a directive control. Directive controls are policies or guidelines that provide instructions or procedures for proper behavior and operations. The acceptable use policy will guide the employees on the allowable use of IT equipment, ensuring compliance with both organizations' expectations.

Discussion

5 comments
Sign in to comment
[Removed]Option: B
Oct 23, 2023

B. Preventive control

0timepassOption: D
Dec 18, 2023

D. Directive control

ChangwhaOption: B
Jul 16, 2023

B. Preventive control

SwallowsOption: D
Jun 2, 2024

While preventive controls (option B) aim to prevent incidents from occurring, the primary objective of the recommended action is to provide clear directives to ensure appropriate use of the IT equipment following the business division sale. Therefore, it aligns more closely with the concept of directive control.

analuisamoreiraOption: D
Jun 27, 2024

D. Policy controls are diretive