CISA · Question #178
An IS auditor is planning a review of an organization's cybersecurity incident response maturity. Which of the following methodologies would provide the MOST reliable conclusions?
The correct answer is B. Data analytics testing. Assessing cybersecurity incident response maturity requires evaluating patterns across large volumes of incident records, response times, escalation paths, and remediation actions. Data analytics testing (B) enables objective, comprehensive analysis of these datasets - it can ide
Question
An IS auditor is planning a review of an organization’s cybersecurity incident response maturity. Which of the following methodologies would provide the MOST reliable conclusions?
Options
- AJudgmental sampling
- BData analytics testing
- CVariable sampling
- DCompliance testing
How the community answered
(27 responses)- A7% (2)
- B56% (15)
- C11% (3)
- D26% (7)
Explanation
Assessing cybersecurity incident response maturity requires evaluating patterns across large volumes of incident records, response times, escalation paths, and remediation actions. Data analytics testing (B) enables objective, comprehensive analysis of these datasets - it can identify trends, anomalies, and gaps that human judgment alone might miss, producing evidence-based, reproducible conclusions. Judgmental sampling (A) relies on the auditor's subjective selection of items, introducing bias and limiting coverage. Variable sampling (C) is designed to estimate a quantity within a population (e.g., error rate) and is not suited for maturity assessments. Compliance testing (D) verifies whether specific controls were followed but does not evaluate the effectiveness or maturity of the overall program.
Topics
Community Discussion
No community discussion yet for this question.