CISSP Practice Question (Domain 6: Security Assessment and Testing)
An internal audit team reporting directly to the CISO produces the assessment reports used for regulatory attestation. A regulator challenges the credibility of the results. What is the MOST appropriate action for executive management?
A. Engage an independent third party to validate the disputed findings
B. Restructure audit reporting lines to the board or audit committee
C. Expand testing scope and increase assessment frequency
D. Require management sign-off attestations on every audit report
(Explain your answer for more points in the comments!)
Come back for the answer tomorrow, or study more now!
0
16 comments
Vincent Primiani
7
CISSP Practice Question (Domain 6: Security Assessment and Testing)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by