Certified Information Systems Auditor CISA · Free Practice Question Easy
Question 51
You are an information system auditor of HDA Inc. You are auditing and reviewing an organization's information security policies. In conducting this review, you need to ensure that the policies have primarily been defined based on:
- A A. Risk management results.
- B B. Regulatory compliance requirements.
- C C. Industry best practices.
- D D. Management's preferences and opinions.
Reveal correct answer
Correct answer: A
Explanation
Correct Answer: A. Risk management results. Explanation: Information security policies should be developed and defined based on the organization's specific risk management results. Risk management involves identifying, assessing, and prioritizing risks to the organization's information assets. By understanding the organization's risk landscape, including threats, vulnerabilities, and potential impacts, policies can be crafted to address the identified risks effectively. While regulatory compliance requirements (option B) and industry best practices (option C) are important considerations when developing information security policies, they should be aligned with the organization's risk management results. Compliance with regulations and adherence to industry standards can help ensure that the organization meets the necessary legal and industry requirements, but they should be tailored to address the organization's specific risks. Management's preferences and opinions (option D) should not be the primary basis for defining information security policies. While management's input and support are crucial, policies should be rooted in objective risk assessments and an understanding of the organization's information security needs. In summary, when reviewing an organization's information security policies, an IS auditor should verify that the policies have been primarily defined based on risk management results (option A). This ensures that the policies are tailored to address the organization's specific risks and provide effective protection for its information assets.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
