QuestionQ124

Governance and Management of IT

Which finding concerning an organization's information security policy should be of GREATEST concern to an IS auditor?

Explanation

Information security governance requires clearly defined organizational roles and responsibilities so that security-related decisions, controls, implementation, monitoring, and accountability have designated owners. If these responsibilities are absent, the organization may be unable to establish or enforce an effective information security program.

Community Discussion

No comments yet. Be the first to start the discussion!