CISA · Question #504
Which of the following should be of GREATEST concern to an IS auditor reviewing security standards implemented in an organization?
The correct answer is C. The baseline security standards lack guidelines on patching.. Lacking patching guidelines is the GREATEST concern because unpatched systems represent an active, exploitable vulnerability - it's not just a documentation gap but a direct path for attackers to compromise systems. An IS auditor's primary concern is risk exposure, and missing pa
Question
Which of the following should be of GREATEST concern to an IS auditor reviewing security standards implemented in an organization?
Options
- AThe baseline security standards differ across applications.
- BThe baseline security standards for operating systems are not uniform.
- CThe baseline security standards lack guidelines on patching.
- DThe baseline security standards are at a generic level.
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C77% (20)
- D12% (3)
Explanation
Lacking patching guidelines is the GREATEST concern because unpatched systems represent an active, exploitable vulnerability - it's not just a documentation gap but a direct path for attackers to compromise systems. An IS auditor's primary concern is risk exposure, and missing patch guidance means vulnerabilities may never be remediated, leaving the organization perpetually exposed.
Why the distractors are wrong:
- A (differing standards across applications): Variation by application can be intentional and appropriate - different apps have different risk profiles. Concerning, but not the greatest risk.
- B (non-uniform OS standards): Similar to A; inconsistency is a management challenge but doesn't inherently leave a door open for attackers.
- D (generic-level standards): Generic standards are actually common and acceptable as a starting baseline - organizations typically layer specifics on top. This is a process maturity issue, not an immediate security gap.
Memory tip: Think "patch = action, everything else = documentation." Auditors escalate when the absence of a control creates a real attack surface - missing patch guidance means vulnerabilities stay open indefinitely. If a standard has no teeth (no patching guidance), it cannot protect the organization regardless of how well-organized or consistent everything else is.
Topics
Community Discussion
No community discussion yet for this question.