ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is reviewing an organization's information security policy. The policy states that 'all employees must protect sensitive information' but does not define what constitutes 'sensitive information' or provide examples. What is the MOST likely impact of this policy statement?

  1. AThe policy will be difficult to audit for compliance and effectiveness.
  2. BRegulatory bodies may deem the policy non-compliant due to vagueness.
  3. CThe organization may struggle to implement appropriate technical controls.
  4. DEmployees may inadvertently expose sensitive data due to lack of clarity.
Show answer & explanation

Correct answer: D. Employees may inadvertently expose sensitive data due to lack of clarity.

Without a clear definition or examples of what constitutes 'sensitive information,' employees cannot reliably distinguish between data types. This ambiguity significantly increases the risk that employees will inadvertently mishandle or expose data they don't recognize as sensitive, leading to security incidents.

Why the other options are wrong

  • A. Difficulty in auditing is a consequence, but the direct operational risk of data exposure is more immediate and significant here.
  • B. This is a potential outcome, but the immediate operational risk is employees making incorrect judgments.
  • C. While a consequence, the immediate and most direct impact of undefined terms is on employee behavior and potential data exposure.

Policy Clarity and Definitions

Information security policies must clearly define terms, classifications, and responsibilities to ensure employees understand and can comply with their obligations.

  • Reduces ambiguity and potential for misinterpretation.
  • Enables consistent application of security controls.
  • Crucial for effective employee security awareness.

Memory trick: A 'CLEAR' policy ensures 'C'ompliance, 'L'egibility, 'E'mployee 'A'wareness, and 'R'esponsibility.

More Domain 2: Governance and Management of IT questions