nerdexam
Isaca

CISA · Question #489

An IS auditor evaluating a policy should be MOST concerned about the lack of a:

The correct answer is C. document owner.. A document owner is the most critical missing element because without one, there is no accountable party responsible for maintaining, reviewing, updating, or enforcing the policy - a core governance requirement in any IS audit framework. Why the distractors are wrong: A (distribu

Submitted by fatema_kw· Apr 18, 2026Governance and Management of IT

Question

An IS auditor evaluating a policy should be MOST concerned about the lack of a:

Options

  • Adistribution list.
  • Bversion history.
  • Cdocument owner.
  • Dcreation date.

How the community answered

(31 responses)
  • A
    19% (6)
  • B
    3% (1)
  • C
    71% (22)
  • D
    6% (2)

Explanation

A document owner is the most critical missing element because without one, there is no accountable party responsible for maintaining, reviewing, updating, or enforcing the policy - a core governance requirement in any IS audit framework.

Why the distractors are wrong:

  • A (distribution list): Useful for knowing who received the policy, but the policy can still be governed and enforced without one.
  • B (version history): Helpful for tracking changes over time, but a missing history doesn't break accountability the way a missing owner does.
  • D (creation date): Provides context for the policy's age, but a dated policy with a clear owner can still be actively managed.

Memory tip: Think "owner = accountability." In IS auditing, the RACI model (Responsible, Accountable, Consulted, Informed) is foundational - a policy without an owner has no "A," making the entire governance chain unenforceable. If a control has no owner, it effectively has no one to answer for it.

Topics

#Policy Management#IS Audit Concerns#Accountability#IT Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice