Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard
An organization is preparing for an upcoming regulatory audit. To ensure readiness, the security team conducts internal assessments, reviews all security documentation, and performs mock audits. Despite these efforts, a critical finding from a previous audit—the lack of documented procedures for secure disposal of retired hard drives—has not been fully addressed. This oversight represents a failure in what key aspect of security audits?
- AAudit scope definition
- BAuditor independence
- CEvidence collection
- DRemediation tracking
Show answer & explanationAnswer & explanation
Correct answer: D. Remediation tracking
The failure to address a critical finding from a previous audit indicates a breakdown in the 'remediation tracking' process, where identified issues are monitored until fully resolved.
Why the other options are wrong
- A. Audit scope definition determines what is covered, not how findings are addressed post-audit.
- B. Auditor independence refers to the auditor's objectivity, which is not the issue here.
- C. Evidence collection is part of the audit performance, not the follow-up on findings.
Remediation Tracking
The process of monitoring and managing the resolution of vulnerabilities, deficiencies, or findings identified during security assessments or audits.
- Ensures identified issues are addressed in a timely and effective manner.
- Involves assigning ownership, setting deadlines, and verifying completion.
- Crucial for continuous improvement of security posture.
Memory trick: Audits PLAN, EXECUTE, REPORT, and REMEDIATE.