Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1001 discussion

Actual exam question from Isaca's CISA
Question #: 1001
Topic #: 1
[All CISA Questions]

Which of the following observations noted by an IS auditor reviewing internal IT standards is MOST important to address?

  • A. The standards have no reference to an industry-recognized framework.
  • B. The standards are not detailed in policies and procedures.
  • C. The standards are not readily available to organization-wide users.
  • D. The standards have not been revised within the last year.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
KAP2HURUF
4 months ago
Selected Answer: B
the lack of such a reference does not necessarily mean the standards are inadequate or not being followed.
upvoted 1 times
...
Swallows
5 months ago
Selected Answer: B
Internal IT standards need to be clearly documented in policies and procedures to ensure they are implemented consistently across the organization. If the standards lack detailed documentation in policies and procedures, it can lead to ambiguity, inconsistent interpretation, and difficulty in enforcement.
upvoted 1 times
...
KAP2HURUF
10 months, 3 weeks ago
Selected Answer: A
While having detailed policies and procedures is crucial for implementing and maintaining IT standards effectively, it typically follows the establishment of the standards themselves. First, you need to have well-defined standards that are aligned with industry best practices and organizational needs (addressing observation A). Once the standards are in place, you can work on creating detailed policies and procedures for their implementation and enforcement (addressing observation B).
upvoted 1 times
...
KAP2HURUF
10 months, 3 weeks ago
Selected Answer: B
The effectiveness of IT standards largely depends on how well they are integrated into the organization's policies and procedures. Standards need to be clearly defined and detailed in the organization's policies and procedures to ensure they are understood, implemented, and enforced consistently. Without this detail, there can be a lack of clarity and uniformity in how the standards are applied, leading to potential gaps in compliance, security, and overall IT governance.
upvoted 4 times
...
FAGFUR
1 year ago
Selected Answer: A
Option A is generally considered the most important because it addresses the foundational aspect of aligning IT standards with widely accepted industry frameworks.
upvoted 2 times
...
SuperMax
1 year, 1 month ago
Selected Answer: A
The most important observation to address among the options listed would typically be option A: "The standards have no reference to an industry-recognized framework." This is crucial because industry-recognized frameworks and standards provide a well-established and widely accepted set of best practices for IT governance and security. Failing to reference such frameworks could mean that the internal IT standards lack the necessary foundation to ensure robust security and compliance. However, it's important to note that the importance of addressing each of these observations may vary depending on the specific context and needs of the organization. In some cases, the other options (B, C, or D) could also be important, but option A generally takes precedence in ensuring a strong foundation for IT standards.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...