Isaca Certified Information Systems Auditor CISA Question # 145 Topic 15 Discussion

Isaca Certified Information Systems Auditor CISA Question # 145 Topic 15 Discussion

CISA Exam Topic 15 Question 145 Discussion:
Question #: 145
Topic #: 15

When reviewing an organization's information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:


A.

a risk management process.


B.

an information security framework.


C.

past information security incidents.


D.

industry best practices.


Get Premium CISA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.