Penetration testing is a security practice used to identify vulnerabilities in an organization's information systems by simulating cyberattacks. It is an essential component of IT risk management and internal auditing under The Institute of Internal Auditors (IIA) standards, particularly in the context of IT governance, cybersecurity risk management, and control assurance. Focus on Preventive Controls: Penetration testing evaluates how well preventive controls (e.g., firewalls, encryption, authentication mechanisms) work against potential cyberattacks. According to the IIA Global Technology Audit Guide (GTAG) 11: Developing an IT Audit Plan, testing should emphasize preventive security measures to minimize risks. Management's Response Assessment: The effectiveness of an organization's incident response plan is also evaluated. Management's reaction to simulated cyber threats ensures that detection and response mechanisms are functional and aligned with IIA Standard 2120 - Risk Management and IIA GTAG 1: Information Security Governance. A). Testing should not be announced to anyone within the organization to solicit a real-life response. (Incorrect) Reason: While unannounced tests (e.g., red team exercises) can provide real-world insights, penetration testing should be coordinated with IT and security personnel. IIA GTAG 11 emphasizes structured and ethical testing approaches, ensuring that necessary stakeholders are informed to prevent operational disruptions. B). Testing should take place during heavy operational time periods to test system resilience. (Incorrect) Reason: While resilience testing is important, penetration testing is typically performed in controlled conditions to avoid disrupting business operations. IIA Standard 2130 - Control supports minimizing business risks during testing. C). Testing should be wide in scope and primarily address detective management controls for identifying potential attacks. (Incorrect) Reason: While detection controls (e.g., intrusion detection systems) are important, penetration testing focuses primarily on preventive controls. IIA GTAG 1 and IIA GTAG 11 stress proactive security strategies over purely detective measures. IIA Global Technology Audit Guide (GTAG) 11: Developing an IT Audit Plan - Covers IT security testing, including penetration testing. IIA GTAG 1: Information Security Governance - Emphasizes the role of security assessments. IIA Standard 2120 - Risk Management - Highlights the importance of testing preventive security measures. IIA Standard 2130 - Control - Discusses ensuring operational effectiveness during testing. Explanation of the Correct Answer (D):Analysis of Incorrect Answers:IIA References:Thus, D is the most accurate choice as per IIA guidance.
A data privacy policy outlines how an organization collects, stores, processes, and protects personal data. It should comply with global data protection regulations such as GDPR, CCPA, and IIA guidelines on data security. (1) Stipulations for deleting certain data after a specified period of time. # Correct. Many data protection laws (e.g., GDPR Article 5) require organizations to delete personal data after a defined retention period to reduce data breach risks. (2) Guidance on acceptable methods for collecting personal data. # Correct. A privacy policy must define legal and ethical ways to collect personal data (e.g., user consent, lawful processing). (3) A requirement to retain personal data indefinitely to ensure a complete audit trail. # Incorrect. Retaining personal data indefinitely violates most data privacy regulations (e.g., GDPR Right to Be Forgotten). Data must be stored only for as long as necessary. (4) A description of what constitutes appropriate use of personal data. # Correct. A privacy policy should clearly define how collected data can and cannot be used to prevent misuse and ensure compliance. IIA GTAG - "Auditing Privacy Risks" IIA Standard 2110 - Governance (Data Protection & Privacy) GDPR (General Data Protection Regulation) - Articles 5 & 17 (Data Retention & Deletion) Analysis of Answer Choices:IIA References:Thus, the correct answer is C (1, 2, and 4 only) because data should not be retained indefinitely, and the policy must include data collection, retention, and appropriate usage guidelines.
IIA-CIA-Part3-CN Exam Question 243
下列哪些文件可以提供內部稽核師在完成工作後保存文件的時間長度的資訊?
Correct Answer: C
The retention and maintenance of internal audit engagement records, including the period of time they must be kept, is governed by the internal audit activity's policies and procedures. These policies provide guidance on record retention consistent with organizational requirements, legal and regulatory obligations, and professional standards. The charter (Option A) defines purpose, authority, and responsibility but does not detail document retention. The annual plan (Option B) outlines engagements but not recordkeeping. The quality assurance and improvement program (Option D) addresses continuous improvement and compliance with standards, not retention guidelines. Therefore, the correct source for document retention requirements is internal audit policies (Option C). Reference: IIA Standards - Standard 2330: Documenting Information; Implementation Guide 2330.