nerdexam
Isaca

CISA · Question #519

In a post-implementation review, an IS auditor observes that management did not define operational log requirements for key integrations. Which of the following controls is MOST important to…

The correct answer is A. Retention periods for logs are configured in alignment with organizational requirements. Defining and configuring appropriate log retention periods is the most important control to implement when operational log requirements were not defined. Proper retention ensures that logs are available for troubleshooting, security monitoring, and compliance purposes, forming…

Submitted by chiamaka_o· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

In a post-implementation review, an IS auditor observes that management did not define operational log requirements for key integrations. Which of the following controls is MOST important to implement?

Options

  • ARetention periods for logs are configured in alignment with organizational requirements.
  • BLogs are monitored by security operations on a quarterly basis.
  • CLogs are migrated to long-term storage after 6 months according to organizational procedures.
  • DRead access to logs is reviewed quarterly for appropriateness.

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    3% (1)
  • C
    8% (3)
  • D
    14% (5)

Explanation

Defining and configuring appropriate log retention periods is the most important control to implement when operational log requirements were not defined. Proper retention ensures that logs are available for troubleshooting, security monitoring, and compliance purposes, forming the foundation for effective log management and auditability.

Topics

#Log management#Operational logging#Control implementation#Post-implementation review

Community Discussion

No community discussion yet for this question.

Full CISA Practice