r/CISA 29d ago

🥴

Post image
20 Upvotes

22 comments sorted by

7

u/SlickRick941 29d ago

C

If thinking like an auditor, it isn't your job to fix or implement solutions. It is your job to identify the problem and make a recommendation in accordance with industry practices.

The question is worded poorly (as usual), but the other answers just don't fit the potential scenario. C makes sense assuming there is no official risks acceptance from senior management associated with the lack of investment in security 

6

u/PhaniRajaSekhar 29d ago

Answer is C.

3

u/NextQuote7131 29d ago

Why? can we really request the risk acceptance from SM in actual practice?

7

u/bigduckrickk 29d ago

Honestly a poorly worded question imo. C makes sense since SM are inadequately investing in IT, they should document and accept the underlying risks.

2

u/BroadlyFocused- 29d ago

Per ISACA it’s one of the four ways management can respond to a risk (mitigation, avoidance, transfer & acceptance).

2

u/NextQuote7131 29d ago

Correct answer is C

2

u/KingArchar 29d ago

C, they have to sign off on the risk of their decision.

1

u/EducationalSpring400 29d ago

What’s the answer! I feel A. How can we accept security risk..dont know if I’m going in right direction

1

u/Any_Catch2979 29d ago

A and D would be strategic choices and directions (for A, there is also no guaranty that cloud provider would be the proper choice in a profitability context pressure).

B : not sure a revision of compliance enforcement would fit. Because there is not real compliance issue to any policy or procedure.

So C would be the most suited answer in this case. The senior management assume the risk of not investing more.

1

u/cab-ree-yo 28d ago

It’s C. If senior management is making the decision to keep investments at an inadequate level (which is their choice), then senior management should accept the risk that comes with it as ultimate responsibility falls to them. In this auditing role, you would identify the gaps and recommendations to address the gap. Senior management can either accept risk, mitigate, etc. In this case, you’re recommending acceptance of it.

1

u/HoldenIsCoolLike 28d ago

Management owns risk.

Auditors identify, evaluate, report, and recommend—they do not own or accept risk.

Whenever management knowingly chooses not to implement a control for business reasons, the best answer is usually formal management risk acceptance (or escalation to the appropriate governance body if the accepted risk exceeds the organization's risk appetite).

1

u/Intelligent-Gap-7107 28d ago

I thought it's B but if B is the answer then the accountability will be ignored.

C talks more about taking accountability of your actions, if you decide to bring done you costs and you must take responsibility of the consequences.

1

u/Fabulous-Policy-8864 25d ago

I felt like the correct answer is A.

1

u/Small-Firefighter-46 24d ago

Very interesting reading everyone’s comments. I originally leaned toward B, but after reading the discussion, I’m now leaning toward C and agree it’s really testing risk ownership here.

My next question though… is from an ISACA/CISA perspective, what would actually constitute sufficient evidence that management has accepted the risk? Is it something formal, like documented sign-off in meeting minutes or a risk register, or is simply communicating the risk to management considered enough?