NEW
Font size
WorksheetsCISA Quiz - Week1
Total questions: 10
Worksheet time: 10mins
Which of the following programs would a sound information security policy MOST likely include to handle suspected intrusions?
Response
Correction
Detection
Monitoring
The development of an IS security policy is ultimately the responsibility of the:
IS department.
security committee.
security administrator.
board of directors.
An IS auditor finds that not all employees are aware of the enterprise's information security policy. The IS auditor should conclude that:
this lack of knowledge may lead to unintentional disclosure of sensitive information.
information security is not critical to all functions.
IS audit should provide security training to the employees.
the audit finding will cause management to provide continuous training to staff.
The rate of change in technology increases the importance of:
outsourcing the IS function.
implementing and enforcing good processes.
hiring personnel willing to make a career within the organization.
meeting user requirements.
The PRIMARY objective of an audit of IT security policies is to ensure that:
they are distributed and available to all staff.
security and control policies support business and IT objectives.
there is a published organizational chart with functional descriptions.
duties are appropriately segregated.
Which of the following is the GREATEST risk of an inadequate policy definition for ownership of data and systems?
User management coordination does not exist.
Specific user accountability cannot be established.
Unauthorized users may have access to originate, modify or delete data.
Audit recommendations may not be implemented.
The advantage of a bottom-up approach to the development of organizational policies is that the policies:
are developed for the organization as a whole.
are more likely to be derived as a result of a risk assessment.
will not conflict with overall corporate policy.
ensure consistency across the organization.
When reviewing an organization's strategic IT plan an IS auditor should expect to find:
an assessment of the fit of the organization's application portfolio with business objectives.
actions to reduce hardware procurement cost.
a listing of approved suppliers of IT contract resources.
a description of the technical architecture for the organization's network perimeter security.
When developing a formal enterprise security program, the MOST critical success factor (CSF) would be the:
establishment of a review board.
creation of a security unit.
effective support of an executive sponsor.
selection of a security process owner.
When reviewing the IT strategic planning process, an IS auditor should ensure that the plan:
incorporates state of the art technology.
addresses the required operational controls.
articulates the IT mission and vision.
specifies project management practices.
