CRISC Certified in Risk and Information Systems ControlGovernanceEasy

A financial services company is preparing for a regulatory audit. The auditors request evidence of how the organization ensures all employees understand and adhere to its information security policies. Which of the following, if implemented, would BEST demonstrate a strong control environment regarding policy adherence?

  1. APosting all information security policies on the company's internal intranet portal.
  2. BDistributing information security policies annually via email to all employees.
  3. CConducting random spot checks of employee workstations for policy violations.
  4. DRequiring all employees to complete mandatory annual training with an attestation of understanding and compliance.
Show answer & explanation

Correct answer: D. Requiring all employees to complete mandatory annual training with an attestation of understanding and compliance.

To demonstrate a strong control environment for policy adherence, it's crucial to prove that employees not only received but also understood and committed to complying with policies. Mandatory annual training followed by an attestation provides clear evidence of this, satisfying auditor requirements more effectively than mere distribution or access.

Why the other options are wrong

  • A. Posting policies provides access but no proof of understanding or acknowledgment by employees.
  • B. Email distribution proves receipt but not necessarily understanding or adherence.
  • C. Spot checks are reactive and punitive; they don't proactively ensure understanding and adherence across the entire employee base.

Policies, Standards, and Procedures

Hierarchical documents that define an organization's objectives, mandatory requirements, and detailed steps for achieving them, respectively.

  • Policies state 'what' should be done.
  • Standards state 'how' to meet policies.
  • Procedures detail 'who, what, when, where, why' for specific tasks.

Memory trick: Train, attest, then rest, for compliance is best.

More Governance questions