Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1387 discussion

Actual exam question from Isaca's CISA
Question #: 1387
Topic #: 1
[All CISA Questions]

Which of the following findings related to an organization's information security policy should be of GREATEST concern to an IS auditor?

  • A. The policy has not been communicated to all staff members and training has not been scheduled.
  • B. The policy has not addressed requirements for regular penetration testing.
  • C. The policy has not defined organizational roles and responsibilities for information security.
  • D. The policy is not developed in accordance with a globally accepted information security standard.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
thusharaj
2 months, 3 weeks ago
While it is crucial that the policy is communicated and that training is provided, this can be addressed relatively quickly once identified. Therefore A is not the correct answer
upvoted 2 times
...
thusharaj
2 months, 3 weeks ago
C is the right answer. If the information security policy has not defined roles and responsibilities, there is a significant risk that critical security tasks may not be performed or may be performed inadequately. This could lead to unclear accountability and a lack of ownership for essential security functions, making the organization vulnerable to security incidents.
upvoted 2 times
...
joehong
7 months, 1 week ago
Selected Answer: C
C is the right answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...