New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Cybersecurity-Audit-Certificate Exam - Topic 1 Question 8 Discussion

Actual exam question for Isaca's Cybersecurity-Audit-Certificate exam
Question #: 8
Topic #: 1
[All Cybersecurity-Audit-Certificate Questions]

Which of the following should an IS auditor do FIRST to ensure cyber security-related legal and regulatory requirements are followed by an organization?

Show Suggested Answer Hide Answer
Suggested Answer: A

The FIRST thing that an IS auditor should do to ensure cyber security-related legal and regulatory requirements are followed by an organization is to determine if the cybersecurity program is mapped to relevant legal and regulatory requirements. This is because mapping the cybersecurity program to relevant legal and regulatory requirements helps to ensure that the organization has identified and addressed all the applicable laws and regulations that affect its cybersecurity posture, such as data protection, privacy, breach notification, etc. Mapping the cybersecurity program to relevant legal and regulatory requirements also helps to evaluate the alignment and compliance of the organization's cybersecurity policies, procedures, controls, and practices with the legal and regulatory requirements. The other options are not the first thing that an IS auditor should do to ensure cyber security-related legal and regulatory requirements are followed by an organization, but rather follow after determining if the cybersecurity program is mapped to relevant legal and regulatory requirements, such as reviewing the most recent legal and regulatory audit report (B), determining if there is a formal process to review changes in legal and regulatory requirements C, or obtaining a list of relevant legal and regulatory requirements (D).


Contribute your Thoughts:

0/2000 characters
Rueben
3 months ago
Agree with A, mapping is crucial!
upvoted 0 times
...
Evelynn
3 months ago
Surprised that D isn't the top choice!
upvoted 0 times
...
Ronny
3 months ago
C makes sense, but isn't it a bit too late?
upvoted 0 times
...
Myra
4 months ago
I think B should come first, though.
upvoted 0 times
...
Elbert
4 months ago
A is definitely the first step!
upvoted 0 times
...
Ozell
4 months ago
I feel like just obtaining a list of requirements isn't enough. We need to ensure they are actively being followed, right?
upvoted 0 times
...
Nikita
4 months ago
I remember a practice question that emphasized the importance of having a formal process for reviewing changes in regulations. That might be crucial.
upvoted 0 times
...
Tequila
4 months ago
I'm not entirely sure, but reviewing the most recent audit report might be a good first step too. It could give insights into what’s already been checked.
upvoted 0 times
...
Glory
5 months ago
I think the first step should be to determine if the cybersecurity program is mapped to legal requirements. It seems logical to start there.
upvoted 0 times
...
Laura
5 months ago
I think I'd want to get a comprehensive list of all the relevant legal and regulatory requirements first, so I have a clear picture of what needs to be covered. Then I can assess the organization's processes from there.
upvoted 0 times
...
Dominga
5 months ago
The key here is to determine if there's a formal process to stay on top of changes in the legal and regulatory landscape. That seems like the most proactive approach to me.
upvoted 0 times
...
Tonette
5 months ago
Hmm, I'm not sure which of these options is the best first step. I guess I'd want to review any recent audit reports to see if there are any known compliance issues before digging deeper.
upvoted 0 times
...
Ashton
5 months ago
This looks like a straightforward question about ensuring legal and regulatory compliance for cybersecurity. I'd start by mapping the organization's cybersecurity program to the relevant requirements to see if they're covered.
upvoted 0 times
...
Joaquin
5 months ago
Increasing the initial delay for the liveness probe could also work, but I'm not sure if that's the most robust solution. I'll have to weigh the pros and cons.
upvoted 0 times
...
Krissy
5 months ago
Hmm, this seems like a tricky one. I'll need to carefully review the scenario and the exhibit to identify the potential issues causing the connectivity problems.
upvoted 0 times
...
Pearly
5 months ago
Okay, let me think this through. If the risk is high enough to be unacceptable, then we need to do something about it, so A seems like the logical choice. I'll go with that.
upvoted 0 times
...

Save Cancel