CISA Exam Question 116
During an external review, an IS auditor observes an inconsistent approach in classifying system criticality within the organization. Which of the following should be recommended as the PRIMARY factor to determine system criticality?
CISA Exam Question 117
Which of the following is the BEST way to detect unauthorized copies of licensed software on systems?
CISA Exam Question 118
An IS auditor concludes that an organization has a quality security policy. Which of the following is MOST important to determine next? The policy must be:
CISA Exam Question 119
An organization has developed mature risk management practices that are followed across all departments What is the MOST effective way for the audit team to leverage this risk management maturity?
CISA Exam Question 120
Secure code reviews as part of a continuous deployment program are which type of control?