nerdexam
Isaca

CISA · Question #61

Which of the following should be the IS auditor's PRIMARY focus when evaluating an organization's offsite storage facility?

The correct answer is A. Adequacy of physical and environmental controls. When evaluating an offsite storage facility, an IS auditor's primary concern should be the adequacy of physical and environmental controls to protect the stored data.

Submitted by kavita_s· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be the IS auditor's PRIMARY focus when evaluating an organization's offsite storage facility?

Options

  • AAdequacy of physical and environmental controls
  • BResults of business continuity plan (BCP) tests
  • CShared facilities
  • DRetention policy and period

How the community answered

(14 responses)
  • A
    86% (12)
  • C
    7% (1)
  • D
    7% (1)

Why each option

When evaluating an offsite storage facility, an IS auditor's primary concern should be the adequacy of physical and environmental controls to protect the stored data.

AAdequacy of physical and environmental controlsCorrect

Physical and environmental controls, such as access restrictions, fire suppression systems, temperature/humidity monitoring, and power backup, directly ensure the security, integrity, and availability of the data and hardware stored at the offsite location. Without these fundamental protections, the facility cannot reliably fulfill its purpose of secure and resilient data storage.

BResults of business continuity plan (BCP) tests

While business continuity plan (BCP) test results are important, they assess the plan's effectiveness, not the fundamental physical and environmental security of the offsite facility itself.

CShared facilities
DRetention policy and period

Concept tested: Offsite storage physical security evaluation

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf

Topics

#Offsite Storage#Physical Security#Environmental Controls#IS Audit Focus

Community Discussion

No community discussion yet for this question.

Full CISA Practice