CISA · Question #127
Which of the following issues identified during a formal review of an organization's information security policies presents the GREATEST potential risk to the organization?
The correct answer is C. The policies are not aligned with the information security risk appetite.. The greatest risk to an organization is when information security policies are not aligned with its defined risk appetite, as this means controls may not adequately address the risks the organization is willing to accept or mitigate.
Question
Which of the following issues identified during a formal review of an organization's information security policies presents the GREATEST potential risk to the organization?
Options
- AThe policies have not been reviewed by the risk management committee.
- BThe policies are not based on industry best practices for information security.
- CThe policies are not aligned with the information security risk appetite.
- DThe policies are not available to key risk stakeholders.
How the community answered
(55 responses)- A5% (3)
- B24% (13)
- C62% (34)
- D9% (5)
Why each option
The greatest risk to an organization is when information security policies are not aligned with its defined risk appetite, as this means controls may not adequately address the risks the organization is willing to accept or mitigate.
While policies should ideally be reviewed by a risk management committee, a lack of review, while a weakness, is less critical than the fundamental misalignment with the organization's risk tolerance.
Not being based on industry best practices can lead to weaknesses, but best practices are a guide; the ultimate measure of policy effectiveness is its alignment with the organization's unique risk profile and appetite.
Information security policies should be a direct reflection of the organization's information security risk appetite, which defines the level of risk the organization is willing to accept. If policies are not aligned with this appetite, the controls implemented may be insufficient or excessive, failing to protect critical assets appropriately or imposing unnecessary burdens, leading to either unmanaged risks or inefficient resource allocation.
Policies not being available to key stakeholders is a significant communication and awareness issue, but it's secondary to the policies themselves being fundamentally misaligned with the organization's risk tolerance.
Concept tested: Information security policy alignment with risk appetite
Topics
Community Discussion
No community discussion yet for this question.