CISA · Question #519
In a post-implementation review, an IS auditor observes that management did not define operational log requirements for key integrations. Which of the following controls is MOST important to…
The correct answer is A. Retention periods for logs are configured in alignment with organizational requirements. Defining and configuring appropriate log retention periods is the most important control to implement when operational log requirements were not defined. Proper retention ensures that logs are available for troubleshooting, security monitoring, and compliance purposes, forming…
Question
In a post-implementation review, an IS auditor observes that management did not define operational log requirements for key integrations. Which of the following controls is MOST important to implement?
Options
- ARetention periods for logs are configured in alignment with organizational requirements.
- BLogs are monitored by security operations on a quarterly basis.
- CLogs are migrated to long-term storage after 6 months according to organizational procedures.
- DRead access to logs is reviewed quarterly for appropriateness.
How the community answered
(36 responses)- A75% (27)
- B3% (1)
- C8% (3)
- D14% (5)
Explanation
Defining and configuring appropriate log retention periods is the most important control to implement when operational log requirements were not defined. Proper retention ensures that logs are available for troubleshooting, security monitoring, and compliance purposes, forming the foundation for effective log management and auditability.
Topics
Community Discussion
No community discussion yet for this question.