Greatest concern in information security policy findings?

Information Security Governance
Answer Correct answer: C — The policy has not defined organizational roles and responsibilities for information security.

Which of the following findings related to an organization's information security policy should be of GREATEST concern to an IS auditor?

  1. The policy has not been communicated to all staff members and training has not been scheduled.
  2. The policy has not addressed requirements for regular penetration testing.
  3. The policy has not defined organizational roles and responsibilities for information security. Correct Answer
  4. The policy is not developed in accordance with a globally accepted information security standard.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prioritization of policy deficiencies, where the trap is choosing operational gaps (like training) over the foundational absence of accountability structures.

An IS auditor must prioritize foundational gaps in information security policies. The consensus is that undefined roles and responsibilities pose the highest risk due to lack of accountability.

Choosing A (lack of communication/training) is common, but this is an operational fixable issue, whereas undefined roles (C) is a fundamental structural failure.

Community Discussion (3 comments)

thusharaj 👍 2
While it is crucial that the policy is communicated and that training is provided, this can be addressed relatively quickly once identified. Therefore A is not the correct answer
thusharaj 👍 2
C is the right answer. If the information security policy has not defined roles and responsibilities, there is a significant risk that critical security tasks may not be performed or may be performed inadequately. This could lead to unclear accountability and a lack of ownership for essential security functions, making the organization vulnerable to security incidents.
joehong 👍 3 Selected: C
C is the right answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because defining roles and responsibilities is the foundation of any security program. Without clear ownership, critical tasks are neglected, leading to unmitigated risks and lack of accountability during incidents.

Why the Other Options Are Wrong

Option A is operational and can be remedied quickly. Option B is a specific control requirement, but less critical than the overall governance structure. Option D is desirable for alignment but not as immediately risky as having no one responsible for security.

Community Comment Notes

Comments highlight that while communication (A) is important, it is secondary to the structural risk of undefined roles (C). The community emphasizes that lack of ownership makes the organization vulnerable to security incidents.

Exam Strategy

When prioritizing findings, always look for foundational or governance issues first. A policy without defined roles is useless, whereas a policy that isn't communicated yet can be fixed with a simple email or meeting.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide