exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1038 discussion

Actual exam question from Isaca's CISA
Question #: 1038
Topic #: 1
[All CISA Questions]

An IS auditor assessing an organization’s information systems needs to understand management’s approach regarding controls. Which documentation should the auditor review FIRST?

  • A. Policies
  • B. Standards
  • C. Guidelines
  • D. Procedures
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
3008
1 month ago
policies > standards > guardline > procedures
upvoted 1 times
...
FAGFUR
1 month, 4 weeks ago
Selected Answer: A
When assessing an organization's information systems and understanding management's approach to controls, the IS auditor should review policies FIRST. Policies provide the overarching framework and high-level guidance for establishing controls within an organization. They define the organization's intent, objectives, and expectations regarding information security and control measures. After reviewing policies, an auditor may then delve into more detailed documentation such as standards, guidelines, and procedures to understand how these policies are implemented and operationalized within the organization. Policies serve as the foundation for the development of more detailed control documentation.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago