nerdexam
Isaca

CISM · Question #865

An organization's information security manager should PRIMARILY leverage its internal audit function to:

The correct answer is B. identify control gaps. Internal audit provides an independent, objective evaluation of controls free from the operational biases of the security team. The primary value this independence offers the information security manager is an unbiased identification of control gaps-areas where controls are…

Submitted by skyler.x· Apr 18, 2026Information Security Governance

Question

An organization's information security manager should PRIMARILY leverage its internal audit function to:

Options

  • Areview policies and procedures.
  • Bidentify control gaps.
  • Cjustify security funding.
  • Dobtain security certification.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    75% (27)
  • C
    14% (5)
  • D
    8% (3)

Explanation

Internal audit provides an independent, objective evaluation of controls free from the operational biases of the security team. The primary value this independence offers the information security manager is an unbiased identification of control gaps-areas where controls are absent, ineffective, or inadequate. Reviewing policies and procedures is part of the audit process but is a means, not the primary benefit. Justifying security funding and obtaining certification are outcomes that may follow from audit findings but are not the core purpose of leveraging the internal audit function.

Topics

#Internal Audit#Control Gaps#Security Assurance#Governance Oversight

Community Discussion

No community discussion yet for this question.

Full CISM Practice