CISA · Question #163
Which of the following should an IS auditor recommend be done FIRST when an organization is planning to implement an IT compliance program?
The correct answer is B. Identify applicable laws, regulations, and standards. This is the foundation for any compliance program, as it ensures that the organization is aware of the legal and regulatory requirements it must adhere to. Once the relevant laws, regulations, and standards are identified, the organization can then proceed with further steps, suc
Question
Which of the following should an IS auditor recommend be done FIRST when an organization is planning to implement an IT compliance program?
Options
- AAnalyze historical compliance-related audit findings
- BIdentify applicable laws, regulations, and standards
- CResearch and purchase an industry-recognized IT compliance tool
- DIdentify staff training needs related to compliance requirements
How the community answered
(36 responses)- A6% (2)
- B89% (32)
- C3% (1)
- D3% (1)
Explanation
This is the foundation for any compliance program, as it ensures that the organization is aware of the legal and regulatory requirements it must adhere to. Once the relevant laws, regulations, and standards are identified, the organization can then proceed with further steps, such as addressing past audit findings, selecting tools, or providing staff training to meet those compliance Without understanding the applicable requirements, any further efforts may be misaligned or
Topics
Community Discussion
No community discussion yet for this question.