Isaca Certified Information Systems Auditor CISA Question # 393 Topic 40 Discussion
CISA Exam Topic 40 Question 393 Discussion:
Question #: 393
Topic #: 40
Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s information security governance?
A.
Risk assessments of information assets are not periodically performed.
B.
All Control Panel Items
C.
The information security policy does not extend to service providers.
D.
There is no process to measure information security performance.
E.
The information security policy is not reviewed by executive management.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit