ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is auditing an organization's information security policy framework. During the review, the CISA notes that the organization's security policies are high-level statements of management's intent, while the security procedures provide detailed, step-by-step instructions for employees. Which of the following is the MOST critical finding for the CISA to report?

  1. AThere is no evidence of regular policy review and updates.
  2. BThe policies lack specific technical implementation details.
  3. CThe procedures are too granular and may hinder operational flexibility.
  4. DThe security standards, which bridge policies and procedures, are missing.
Show answer & explanation

Correct answer: D. The security standards, which bridge policies and procedures, are missing.

Security standards are crucial as they translate high-level policies into specific requirements, guiding the creation of detailed procedures. Without standards, there's a gap between management's intent and practical implementation, leading to inconsistencies and potential control weaknesses.

Why the other options are wrong

  • A. While important, the absence of a bridging document (standards) is a more fundamental structural issue than the frequency of review.
  • B. Policies are intentionally high-level; technical details belong in standards or procedures.
  • C. Procedures are meant to be granular; this is not necessarily a critical finding unless it demonstrably causes significant operational issues.

Security Policy Framework

A hierarchical structure of documents that guides an organization's information security efforts, typically including policies, standards, guidelines, and procedures.

  • Policies are high-level statements of management intent.
  • Standards provide mandatory requirements for implementing policies.
  • Procedures offer step-by-step instructions for tasks.

Memory trick: Policy sets the 'WHAT', Standard sets the 'HOW MUCH', Procedure sets the 'STEP-BY-STEP'.

More Domain 5: Protection of Information Assets questions