ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy
An IS auditor is evaluating the organization's approach to information security governance. The audit objective is to determine if security objectives align with business objectives. Which of the following activities is MOST effective for the auditor to perform to achieve this objective?
- AReviewing recent security incident reports and their resolution times.
- BExamining the organization's strategic business plan and comparing it with the information security strategy.
- CInterviewing IT security personnel about their daily operational tasks.
- DTesting the effectiveness of access controls on critical business applications.
Show answer & explanationAnswer & explanation
Correct answer: B. Examining the organization's strategic business plan and comparing it with the information security strategy.
To determine if security objectives align with business objectives, the most direct and effective approach is to compare the formal strategic documents of both areas. Reviewing security incident reports, interviewing IT personnel, or testing controls are operational activities that do not directly assess strategic alignment.
Why the other options are wrong
- A. Incident reports provide data on operational effectiveness, not strategic alignment.
- C. Interviews with IT security personnel focus on operational details, not high-level strategic alignment.
- D. Testing access controls evaluates operational effectiveness of a specific control, not strategic alignment.
Strategic Alignment Audit
An audit focused on evaluating whether IT and information security strategies support and are consistent with the overall business objectives and strategy.
- Ensures IT investments support business goals.
- Identifies gaps between strategic plans.
- Crucial for effective governance.
Memory trick: Strategic alignment is like two gears, business and security, turning perfectly together.