CISA · Question #24
Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?
The correct answer is A. Security policies are not applicable across all business units.. An IS auditor's greatest concern regarding policy compliance is when security policies lack universal applicability across all business units, indicating significant gaps in organizational security coverage.
Question
Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?
Options
- ASecurity policies are not applicable across all business units.
- BEnd users are not required to acknowledge security policy training.
- CThe security policy has not been reviewed within the past year.
- DSecurity policy documents are available on a public domain website.
How the community answered
(43 responses)- A60% (26)
- B12% (5)
- C23% (10)
- D5% (2)
Why each option
An IS auditor's greatest concern regarding policy compliance is when security policies lack universal applicability across all business units, indicating significant gaps in organizational security coverage.
If security policies are not applicable across all business units, it means there are parts of the organization where security controls may be absent, inconsistent, or unenforced, leaving critical assets or data vulnerable. This creates significant organizational risk and a systemic failure in maintaining a consistent security posture, making it a primary concern for an IS auditor due to the potential for unaddressed threats.
While requiring acknowledgment of security policy training is good practice for accountability, its absence is less critical than fundamental policy applicability across the entire organization.
An outdated security policy can lead to gaps, but it is less immediately concerning than a policy that fundamentally doesn't cover all parts of the business, creating known unprotected areas.
Making security policy documents publicly available could be a concern for sensitive internal details, but it doesn't directly indicate a failure in applying security controls or compliance within the organization itself.
Concept tested: Policy scope and organizational risk
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12r1.pdf
Topics
Community Discussion
No community discussion yet for this question.