nerdexam
Isaca

CISA · Question #545

Which of the following would BEST enable an IS auditor to evaluate an organization's level of compliance with a new cryptographic regulatory requirement?

The correct answer is C. Conducting a gap assessment. A gap assessment is the best method because it systematically compares the organization's current cryptographic practices and controls against the specific requirements of the new regulation, producing a measurable picture of what is compliant and what is not. Option A (privacy…

Submitted by lucia.co· Apr 18, 2026Information System Auditing Process

Question

Which of the following would BEST enable an IS auditor to evaluate an organization's level of compliance with a new cryptographic regulatory requirement?

Options

  • APerforming a privacy risk assessment
  • BInterviewing IT and cybersecurity management
  • CConducting a gap assessment
  • DReviewing IT policies for evidence of compliance

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    13% (5)
  • C
    80% (32)
  • D
    5% (2)

Explanation

A gap assessment is the best method because it systematically compares the organization's current cryptographic practices and controls against the specific requirements of the new regulation, producing a measurable picture of what is compliant and what is not. Option A (privacy risk assessment) focuses on privacy risk broadly, not cryptographic regulatory compliance specifically. Option B (interviewing management) provides qualitative opinions but lacks the structured evidence needed to evaluate compliance levels. Option D (reviewing policies) only confirms documented intent-not whether the controls are actually implemented or effective.

Topics

#Compliance Auditing#Regulatory Compliance#Gap Assessment#Audit Procedures

Community Discussion

No community discussion yet for this question.

Full CISA Practice