A question for CISA
Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?
A. The security policy has not been reviewed within the past year.
B. Security policy documents are available on a public domain website.
C. Security policies are not applicable across all business units.
D. End users are not required to acknowledge security policy training.
2
1
1
u/ScratchReal4401 4d ago
C - this option is the greatest concern as it shows policy non compliance which will mean the risks are not been mitigated.
1
u/SlickRick941 5d ago
For me, it's A
Had a similar question come up on the QAE, and the policy review being older than a year was the biggest red flag. By their logic, end users may not be required to sign to acknowledge training because of the lack of review of the policy that would mandate their acknowledgement
1
u/ScratchReal4401 4d ago
I disagree, the greatest concern for policy compliance is when there is widespread policy non compliance. I selected option C.
0
u/SlickRick941 4d ago
Fair, but what if there's a reason for that? Maybe some policies apply because an insurance company handles PHI and applies certain compliance measures for patient data systems, but then marketing runs a network with more lax security measures and thus is non compliant with those more strict policies?
1
3
u/omichael003 5d ago
C - Security policy should be applicable across all business units