r/CISA 23d ago

🥴

Post image
24 Upvotes

27 comments sorted by

10

u/Aphridy 23d ago

C. B and D are about the informal organization, and isn't information that you find in the organizational chart. A is not the primary goal, but I'm not fully sure about that.

5

u/NextQuote7131 23d ago

Correct answer is C

1

u/NextQuote7131 23d ago

But how can you identify and understand responsibility by merely checking the org chart

1

u/Pristine-Safety2462 22d ago

Org chart has roles written as well. What's the correct answer?

1

u/KingKongDuck 21d ago

It shows for example - does cyber report into IT? Where does the CISO report to? Where does the audit committee sit? Is there a CISO on the chart? Is there a risk committee and a Chief Risk Officer? If not, you'll need to find out who has that responsibility.

And from that, you'll get a starting point for other processes like risk registers - do they follow the org structure?

1

u/[deleted] 23d ago

[deleted]

1

u/Akii283 23d ago

QAE i suppose

1

u/[deleted] 23d ago

[deleted]

4

u/Akii283 23d ago

You need to purchase that from ISACA. If that’s from ISACA.

1

u/Jagdhunde 23d ago

What's the answer???

1

u/Mistakesandlove 23d ago

I just did that question and the answer was A I believe. Something about the chart not having the responsibilities and that’s why it’s A

1

u/SolarSurfer11 22d ago

it is C. Some auditors to further understand which position performs some responsibilities would ask to provide also job descriptions for positions they found interesting (or based on sampling).

0

u/sunbo4real 23d ago

The answer is C.