nerdexam
Isaca

CISA · Question #46

Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization's information security policy?

The correct answer is A. Business objectives. The most critical consideration for an IS auditor when assessing an information security policy is its alignment with the organization's overarching business objectives.

Submitted by satoshi_tk· Apr 18, 2026Governance and Management of IT

Question

Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization’s information security policy?

Options

  • ABusiness objectives
  • BAlignment with the IT tactical plan
  • CCompliance with industry best practice
  • DIT steering committee minutes

How the community answered

(26 responses)
  • A
    96% (25)
  • C
    4% (1)

Why each option

The most critical consideration for an IS auditor when assessing an information security policy is its alignment with the organization's overarching business objectives.

ABusiness objectivesCorrect

An information security policy must directly support and enable the organization's business objectives; without this alignment, security measures may hinder operations or protect information assets that are not critical to the business. The policy's adequacy is fundamentally measured by its ability to effectively protect the information assets essential for achieving the organization's strategic goals.

BAlignment with the IT tactical plan

While alignment with the IT tactical plan is important, the IT plan itself should align with business objectives, making business objectives the foundational and overriding concern.

CCompliance with industry best practice

Compliance with industry best practice is a good benchmark, but practices must be tailored to the specific business context and objectives to be truly adequate and effective.

DIT steering committee minutes

IT steering committee minutes provide oversight records but do not inherently define the adequacy of the policy's content in relation to the organization's specific business needs.

Concept tested: Information security policy alignment

Source: https://www.isaca.org/resources/isaca-journal/isaca-journal-archives/2012/volume-2/assessing-an-organizations-information-security-policy

Topics

#Information security policy#Business alignment#IT governance#Policy assessment

Community Discussion

No community discussion yet for this question.

Full CISA Practice