nerdexam
Isaca

CISA · Question #218

Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization's cybersecurity posture?

The correct answer is D. Maturity assessment results. A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a multi-dimensional

Submitted by daniela_cl· Apr 18, 2026Information System Auditing Process

Question

Which of the following would provide an IS auditor with the MOST comprehensive understanding of an organization’s cybersecurity posture?

Options

  • AVulnerability assessment results
  • BIncident response metrics
  • CInternal audit findings
  • DMaturity assessment results

How the community answered

(58 responses)
  • A
    5% (3)
  • B
    16% (9)
  • C
    9% (5)
  • D
    71% (41)

Explanation

A maturity assessment (e.g., against CMMI, NIST CSF, or CMMC) evaluates the organization's cybersecurity capabilities holistically across people, processes, and technology - and rates how consistently and repeatably those capabilities are applied. It provides a multi-dimensional view of current state and gaps. Vulnerability assessments (A) are point-in-time technical scans. Incident response metrics (B) reflect only one capability domain. Internal audit findings (C) are also point-in-time and scope-limited. Only a maturity assessment provides the breadth and depth needed for a comprehensive posture evaluation.

Topics

#Cybersecurity Posture#Maturity Assessment#Audit Techniques#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice