CISA · Question #489
An IS auditor evaluating a policy should be MOST concerned about the lack of a:
The correct answer is C. document owner.. A document owner is the most critical missing element because without one, there is no accountable party responsible for maintaining, reviewing, updating, or enforcing the policy - a core governance requirement in any IS audit framework. Why the distractors are wrong: A (distribu
Question
An IS auditor evaluating a policy should be MOST concerned about the lack of a:
Options
- Adistribution list.
- Bversion history.
- Cdocument owner.
- Dcreation date.
How the community answered
(31 responses)- A19% (6)
- B3% (1)
- C71% (22)
- D6% (2)
Explanation
A document owner is the most critical missing element because without one, there is no accountable party responsible for maintaining, reviewing, updating, or enforcing the policy - a core governance requirement in any IS audit framework.
Why the distractors are wrong:
- A (distribution list): Useful for knowing who received the policy, but the policy can still be governed and enforced without one.
- B (version history): Helpful for tracking changes over time, but a missing history doesn't break accountability the way a missing owner does.
- D (creation date): Provides context for the policy's age, but a dated policy with a clear owner can still be actively managed.
Memory tip: Think "owner = accountability." In IS auditing, the RACI model (Responsible, Accountable, Consulted, Informed) is foundational - a policy without an owner has no "A," making the entire governance chain unenforceable. If a control has no owner, it effectively has no one to answer for it.
Topics
Community Discussion
No community discussion yet for this question.