nerdexam
Isaca

CISA · Question #574

Which of the following should be the GREATEST concern to an IS auditor evaluating an organization's policies?

The correct answer is B. Policies do not identify adequate controls or processes to protect the organization.. Policies exist to define the controls and processes that protect the organization from risk. If policies do not identify adequate controls, they fail their fundamental purpose - leaving the organization exposed to threats regardless of how well-formatted or frequently reviewed th

Submitted by manish99· Apr 18, 2026Governance and Management of IT

Question

Which of the following should be the GREATEST concern to an IS auditor evaluating an organization's policies?

Options

  • APolicies are not reviewed by the chief information officer (CIO).
  • BPolicies do not identify adequate controls or processes to protect the organization.
  • CPolicies are not updated on an annual basis.
  • DPolicies are not formally acknowledged and signed by employees.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    78% (25)
  • C
    6% (2)
  • D
    13% (4)

Explanation

Policies exist to define the controls and processes that protect the organization from risk. If policies do not identify adequate controls, they fail their fundamental purpose - leaving the organization exposed to threats regardless of how well-formatted or frequently reviewed they are. This is a substantive deficiency. Not being reviewed by the CIO (A) is a governance concern but not as critical as inadequate content. Annual review cycles (C) are a best practice but policies may still be adequate if not changed yearly. Employee acknowledgment (D) is important for enforceability but a policy with solid controls that isn't signed is still more protective than a signed policy with inadequate controls.

Topics

#IS Audit#Policy Evaluation#Control Adequacy#Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice