nerdexam
Isaca

CISA · Question #24

Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?

The correct answer is A. Security policies are not applicable across all business units.. An IS auditor's greatest concern regarding policy compliance is when security policies lack universal applicability across all business units, indicating significant gaps in organizational security coverage.

Submitted by luis.pe· Apr 18, 2026Governance and Management of IT

Question

Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?

Options

  • ASecurity policies are not applicable across all business units.
  • BEnd users are not required to acknowledge security policy training.
  • CThe security policy has not been reviewed within the past year.
  • DSecurity policy documents are available on a public domain website.

How the community answered

(43 responses)
  • A
    60% (26)
  • B
    12% (5)
  • C
    23% (10)
  • D
    5% (2)

Why each option

An IS auditor's greatest concern regarding policy compliance is when security policies lack universal applicability across all business units, indicating significant gaps in organizational security coverage.

ASecurity policies are not applicable across all business units.Correct

If security policies are not applicable across all business units, it means there are parts of the organization where security controls may be absent, inconsistent, or unenforced, leaving critical assets or data vulnerable. This creates significant organizational risk and a systemic failure in maintaining a consistent security posture, making it a primary concern for an IS auditor due to the potential for unaddressed threats.

BEnd users are not required to acknowledge security policy training.

While requiring acknowledgment of security policy training is good practice for accountability, its absence is less critical than fundamental policy applicability across the entire organization.

CThe security policy has not been reviewed within the past year.

An outdated security policy can lead to gaps, but it is less immediately concerning than a policy that fundamentally doesn't cover all parts of the business, creating known unprotected areas.

DSecurity policy documents are available on a public domain website.

Making security policy documents publicly available could be a concern for sensitive internal details, but it doesn't directly indicate a failure in applying security controls or compliance within the organization itself.

Concept tested: Policy scope and organizational risk

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12r1.pdf

Topics

#Security Policy#Policy Compliance#IT Governance#Audit Concerns

Community Discussion

No community discussion yet for this question.

Full CISA Practice