CISM · Question #865
An organization's information security manager should PRIMARILY leverage its internal audit function to:
The correct answer is B. identify control gaps. Internal audit provides an independent, objective evaluation of controls free from the operational biases of the security team. The primary value this independence offers the information security manager is an unbiased identification of control gaps-areas where controls are…
Question
An organization's information security manager should PRIMARILY leverage its internal audit function to:
Options
- Areview policies and procedures.
- Bidentify control gaps.
- Cjustify security funding.
- Dobtain security certification.
How the community answered
(36 responses)- A3% (1)
- B75% (27)
- C14% (5)
- D8% (3)
Explanation
Internal audit provides an independent, objective evaluation of controls free from the operational biases of the security team. The primary value this independence offers the information security manager is an unbiased identification of control gaps-areas where controls are absent, ineffective, or inadequate. Reviewing policies and procedures is part of the audit process but is a means, not the primary benefit. Justifying security funding and obtaining certification are outcomes that may follow from audit findings but are not the core purpose of leveraging the internal audit function.
Topics
Community Discussion
No community discussion yet for this question.