CAS-001 · Question #336
An external auditor has found that IT security policies in the organization are not maintained and in some cases are nonexistent. As a result of the audit findings, the CISO has been tasked with the…
The correct answer is D. eGRC. An eGRC (electronic Governance, Risk, and Compliance) platform is a software tool specifically designed to manage the full lifecycle of IT security policies - including creation, review, approval, distribution, exception handling, and retirement/versioning. Unlike frameworks…
Question
An external auditor has found that IT security policies in the organization are not maintained and in some cases are nonexistent. As a result of the audit findings, the CISO has been tasked with the objective of establishing a mechanism to manage the lifecycle of IT security policies. Which of the following can be used to BEST achieve the CISO's objectives?
Options
- ACoBIT
- BUCF
- CISO 27002
- DeGRC
How the community answered
(37 responses)- A3% (1)
- B14% (5)
- C8% (3)
- D76% (28)
Explanation
An eGRC (electronic Governance, Risk, and Compliance) platform is a software tool specifically designed to manage the full lifecycle of IT security policies - including creation, review, approval, distribution, exception handling, and retirement/versioning. Unlike frameworks (CoBIT, ISO 27002) or mapping tools (UCF), an eGRC solution provides workflow automation and a centralized repository that enforces process around when policies are created, who approves them, how they are communicated, and when they expire or are reviewed. This directly addresses the CISO's objective of establishing a mechanism to manage policy lifecycle.
Topics
Community Discussion
No community discussion yet for this question.