Greatest concern in information security policy findings?
Which of the following findings related to an organization's information security policy should be of GREATEST concern to an IS auditor?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prioritization of policy deficiencies, where the trap is choosing operational gaps (like training) over the foundational absence of accountability structures.
An IS auditor must prioritize foundational gaps in information security policies. The consensus is that undefined roles and responsibilities pose the highest risk due to lack of accountability.
Choosing A (lack of communication/training) is common, but this is an operational fixable issue, whereas undefined roles (C) is a fundamental structural failure.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is correct because defining roles and responsibilities is the foundation of any security program. Without clear ownership, critical tasks are neglected, leading to unmitigated risks and lack of accountability during incidents.Why the Other Options Are Wrong
Option A is operational and can be remedied quickly. Option B is a specific control requirement, but less critical than the overall governance structure. Option D is desirable for alignment but not as immediately risky as having no one responsible for security.Community Comment Notes
Comments highlight that while communication (A) is important, it is secondary to the structural risk of undefined roles (C). The community emphasizes that lack of ownership makes the organization vulnerable to security incidents.Exam Strategy
When prioritizing findings, always look for foundational or governance issues first. A policy without defined roles is useless, whereas a policy that isn't communicated yet can be fixed with a simple email or meeting.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →