Certified Information Systems Auditor CISA · Free Practice Question Medium

Question 73

You are an information system auditor of HDA Inc. You are auditing and assessing the adequacy of an organization's information security policy. Which of the following sources of information would be the most suitable for you to use in making this determination?
  • A A. Industry best practices.
  • B B. Internal audit reports.
  • C C. Results of the risk management process.
  • D D. Employee surveys.
Reveal correct answer

Correct answer: C

Explanation

Correct Answer: C. Results of the risk management process. Explanation: When evaluating the adequacy of an organization's information security policy, the best source of information for an IS auditor is the results of the risk management process. Risk management helps identify and assess potential risks to the organization's information assets and determines appropriate controls to mitigate those risks. By reviewing the results of the risk management process, the auditor can understand the specific risks identified and the controls implemented to address those risks. This information is crucial in assessing the adequacy and effectiveness of the organization's information security policy. Option A, industry best practices, can provide valuable insights and benchmarks for developing an information security policy. However, it may not necessarily reflect the organization's unique risk profile and requirements. Internal audit reports (option B) can provide additional information about the organization's control environment but may not specifically address the adequacy of the information security policy. Employee surveys (option D) can capture subjective opinions and perceptions but may not provide comprehensive and objective evidence about the policy's adequacy. In summary, when determining the adequacy of an organization's information security policy, the best source of information for an IS auditor is the results of the risk management process (option C). It provides insight into the identified risks and corresponding controls, allowing the auditor to evaluate the policy's alignment with the organization's risk profile.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need