CISA · Question #46
Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization's information security policy?
The correct answer is A. Business objectives. The most critical consideration for an IS auditor when assessing an information security policy is its alignment with the organization's overarching business objectives.
Question
Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization’s information security policy?
Options
- ABusiness objectives
- BAlignment with the IT tactical plan
- CCompliance with industry best practice
- DIT steering committee minutes
How the community answered
(26 responses)- A96% (25)
- C4% (1)
Why each option
The most critical consideration for an IS auditor when assessing an information security policy is its alignment with the organization's overarching business objectives.
An information security policy must directly support and enable the organization's business objectives; without this alignment, security measures may hinder operations or protect information assets that are not critical to the business. The policy's adequacy is fundamentally measured by its ability to effectively protect the information assets essential for achieving the organization's strategic goals.
While alignment with the IT tactical plan is important, the IT plan itself should align with business objectives, making business objectives the foundational and overriding concern.
Compliance with industry best practice is a good benchmark, but practices must be tailored to the specific business context and objectives to be truly adequate and effective.
IT steering committee minutes provide oversight records but do not inherently define the adequacy of the policy's content in relation to the organization's specific business needs.
Concept tested: Information security policy alignment
Source: https://www.isaca.org/resources/isaca-journal/isaca-journal-archives/2012/volume-2/assessing-an-organizations-information-security-policy
Topics
Community Discussion
No community discussion yet for this question.