CISA · Question #574
Which of the following should be the GREATEST concern to an IS auditor evaluating an organization's policies?
The correct answer is B. Policies do not identify adequate controls or processes to protect the organization.. Policies exist to define the controls and processes that protect the organization from risk. If policies do not identify adequate controls, they fail their fundamental purpose - leaving the organization exposed to threats regardless of how well-formatted or frequently reviewed th
Question
Which of the following should be the GREATEST concern to an IS auditor evaluating an organization's policies?
Options
- APolicies are not reviewed by the chief information officer (CIO).
- BPolicies do not identify adequate controls or processes to protect the organization.
- CPolicies are not updated on an annual basis.
- DPolicies are not formally acknowledged and signed by employees.
How the community answered
(32 responses)- A3% (1)
- B78% (25)
- C6% (2)
- D13% (4)
Explanation
Policies exist to define the controls and processes that protect the organization from risk. If policies do not identify adequate controls, they fail their fundamental purpose - leaving the organization exposed to threats regardless of how well-formatted or frequently reviewed they are. This is a substantive deficiency. Not being reviewed by the CIO (A) is a governance concern but not as critical as inadequate content. Annual review cycles (C) are a best practice but policies may still be adequate if not changed yearly. Employee acknowledgment (D) is important for enforceability but a policy with solid controls that isn't signed is still more protective than a signed policy with inadequate controls.
Topics
Community Discussion
No community discussion yet for this question.