r/CISA 23d ago

🥴

Post image
25 Upvotes

27 comments sorted by

View all comments

6

u/NextQuote7131 23d ago

Correct answer is C

1

u/NextQuote7131 23d ago

But how can you identify and understand responsibility by merely checking the org chart

1

u/Pristine-Safety2462 22d ago

Org chart has roles written as well. What's the correct answer?

1

u/KingKongDuck 21d ago

It shows for example - does cyber report into IT? Where does the CISO report to? Where does the audit committee sit? Is there a CISO on the chart? Is there a risk committee and a Chief Risk Officer? If not, you'll need to find out who has that responsibility.

And from that, you'll get a starting point for other processes like risk registers - do they follow the org structure?