exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 912 discussion

Actual exam question from Isaca's CISA
Question #: 912
Topic #: 1
[All CISA Questions]

During an information security audit of a mid-sized organization, an IS auditor notes that the organization's information security policy is not sufficient. What is the auditor's BEST recommendation for the organization?

  • A. Obtain an external consultant's support to rewrite the policy.
  • B. Identify and close gaps compared to a best-practice framework.
  • C. Perform a benchmark with competitors’ policies.
  • D. Define roles and responsibilities for regularly updating the policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Swallows
1 month, 2 weeks ago
Selected Answer: B
While defining roles and responsibilities for regularly updating the policy (Option D) is also important for ensuring the policy remains current and relevant, it does not address the immediate need to enhance the policy to meet recognized standards and best practices. Therefore, identifying and closing gaps compared to a best-practice framework (Option B) is the BEST recommendation for addressing the insufficient information security policy.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago