nerdexam
Isaca

CISA · Question #163

Which of the following should an IS auditor recommend be done FIRST when an organization is planning to implement an IT compliance program?

The correct answer is B. Identify applicable laws, regulations, and standards. This is the foundation for any compliance program, as it ensures that the organization is aware of the legal and regulatory requirements it must adhere to. Once the relevant laws, regulations, and standards are identified, the organization can then proceed with further steps, suc

Submitted by minji_kr· Apr 18, 2026Governance and Management of IT

Question

Which of the following should an IS auditor recommend be done FIRST when an organization is planning to implement an IT compliance program?

Options

  • AAnalyze historical compliance-related audit findings
  • BIdentify applicable laws, regulations, and standards
  • CResearch and purchase an industry-recognized IT compliance tool
  • DIdentify staff training needs related to compliance requirements

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    89% (32)
  • C
    3% (1)
  • D
    3% (1)

Explanation

This is the foundation for any compliance program, as it ensures that the organization is aware of the legal and regulatory requirements it must adhere to. Once the relevant laws, regulations, and standards are identified, the organization can then proceed with further steps, such as addressing past audit findings, selecting tools, or providing staff training to meet those compliance Without understanding the applicable requirements, any further efforts may be misaligned or

Topics

#IT compliance program#Regulatory compliance#Compliance framework#Program initiation

Community Discussion

No community discussion yet for this question.

Full CISA Practice