Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 871 discussion

Actual exam question from Isaca's CISA
Question #: 871
Topic #: 1
[All CISA Questions]

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

  • A. Consultation with security staff
  • B. Alignment with an information security framework
  • C. Inclusion of mission and objectives
  • D. Compliance with relevant regulations
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Swallows
5 months, 4 weeks ago
Selected Answer: C
While alignment with an information security framework (Option B) is also important for providing guidance on best practices and standards, it should be guided by the organization's mission and objectives to ensure that security measures are integrated into its overall strategic direction and business processes. Therefore, inclusion of mission and objectives is typically considered the most important factor in information security policy development.
upvoted 1 times
...
takuanism
9 months, 4 weeks ago
Selected Answer: D
should be compliance with regulations first, D should be correct
upvoted 2 times
...
KAP2HURUF
10 months ago
Selected Answer: B
Compliance with regulations is crucial, but it often aligns with and is facilitated by adherence to recognized information security frameworks. Regulations may specify certain requirements, but a well-established framework typically covers a broader set of security controls and practices. In summary, while all the factors mentioned are important, aligning with an information security framework (Option B) provides a strong foundation for developing effective information security policies and procedures that are comprehensive, adaptable, and aligned with industry best practices.
upvoted 2 times
KAP2HURUF
4 months ago
The most important factor when an organization is developing information security policies and procedures is compliance with relevant regulations. Ensuring that policies and procedures are in line with legal and regulatory requirements is critical to avoid legal penalties, fines, and reputational damage. Compliance ensures that the organization meets its external obligations and can operate within the legal framework of its industry and jurisdiction.
upvoted 1 times
...
...
SuperMax
1 year, 1 month ago
Selected Answer: B
The MOST important factor when an organization is developing information security policies and procedures can vary depending on the organization's specific context and priorities. However, in a general sense, option B, "Alignment with an information security framework," is often considered the most critical factor. While consultation with security staff (option A), inclusion of mission and objectives (option C), and compliance with relevant regulations (option D) are also important considerations, they are often influenced by and benefit from the alignment with an information security framework. The framework provides a structured basis for involving security staff, defining objectives, and ensuring regulatory compliance. Additionally, alignment with an information security framework generally implies a holistic and systematic approach to security, which is essential for robust information security policies and procedures.
upvoted 2 times
...
3008
1 year, 3 months ago
Selected Answer: D
Compliance with relevant regulations: Compliance with relevant regulations is the most important factor when developing information security policies and procedures. Organizations must comply with laws, regulations, and industry standards that pertain to information security. Failure to comply with relevant regulations could result in legal and financial penalties and damage to an organization's reputation.
upvoted 3 times
...
BabaP
1 year, 6 months ago
Selected Answer: D
D is better
upvoted 3 times
...
kertyce
1 year, 9 months ago
policies and procedure, not only policies...i will go with B
upvoted 1 times
...
Joloms
1 year, 9 months ago
compliance before framework
upvoted 1 times
...
Joloms
1 year, 9 months ago
D I think it should comply with laws and regulations
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...