Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Cybersecurity-Audit-Certificate Exam - Topic 2 Question 60 Discussion

A cybersecurity audit reveals that an organization's risk management function has the right to overrule business management decisions. Would the IS auditor find this arrangement acceptable?
C) No, because the risk management's oversight function would potentially lose its ability to objectively monitor and measure the business.
A) No, because the risk management function should be the body that makes risk-related decisions for the organization.
B) Yes, because the second line of defense is generally on a higher organizational level than the first line.
D) Yes, because this arrangement ensures adequate oversight and enforcement of risk management in the organization.

Isaca Cybersecurity-Audit-Certificate Exam - Topic 2 Question 60 Discussion

Actual exam question for Isaca's Cybersecurity-Audit-Certificate exam
Question #: 60
Topic #: 2
[All Cybersecurity-Audit-Certificate Questions]

A cybersecurity audit reveals that an organization's risk management function has the right to overrule business management decisions. Would the IS auditor find this arrangement acceptable?

Show Suggested Answer Hide Answer
Suggested Answer: C

The role of risk management is to provide an oversight function, ensuring that the business management's decisions align with the organization's risk appetite and strategy. If the risk management function were to overrule business management decisions, it could compromise its objectivity. This could lead to a conflict of interest and diminish the function's ability to provide unbiased oversight and measurement of business activities.


Contribute your Thoughts:

0/2000 characters
Louvenia
4 days ago
I'm not entirely sure, but I feel like the second line of defense should support the first line, not override it. That could create confusion in decision-making.
upvoted 0 times
...
Lili
9 days ago
I think I saw a similar question in our practice exams. If risk management has too much power, it might compromise their objectivity, right?
upvoted 0 times
...
Evangelina
14 days ago
I remember discussing how the risk management function should ideally advise rather than overrule business decisions. It seems like that would lead to conflicts.
upvoted 0 times
...

Save Cancel