CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 485


Which of the following is the BEST way for an IS auditor to validate that employees have been made aware of the organization's information security policy?

Show Answer
Correct Answer: AB

The best way for an IS auditor to validate that employees have been made aware of the organization's information security policy is to interview employees to determine their level of understanding of the policy. This approach directly assesses employees' awareness and comprehension of the policy, which is crucial for ensuring that they have actually been informed and understand the policy. Simply comparing an employee roster against a list of those who attended security training does not confirm that employees have internalized the information or understood it.

Discussion

5 comments
Sign in to comment
NicklMOption: A
May 3, 2023

should be A

starzuu
Jul 27, 2023

i think B is correct. To "validate" that employees have been made aware, the most objective and straightforward way would be B. A relies on individual employees' ability to recall and explain the policy. therefore it may not accurately reflect whether they were made aware of the policy, especially if some time has passed since they had been told about it.

takuanismOption: A
Jan 13, 2024

It seems A is good answer, I guess...

JongHyunOption: A
May 9, 2024

absolutely A

shalota2Option: B
Jun 10, 2024

I think is B. Because it says that "made aware". Is not saying that effectiviness of information security policies or how much they understand.

RS66Option: B
Jul 5, 2024

why interview hundreds of people while you have a list of people who attended the training? I say B is more logical.