Which of the following is the BEST way for an IS auditor to determine how well an information security program has been implemented throughout the organization? A. Evaluate the percentage of employees who have taken security awareness training. B. Review security awareness training content for completeness. C. Perform security risk assessments for the organization's business units. D. Evaluate the integration of security best practices into business workflow. Â Suggested Answer: C Community Answer: C This question is in CISA Certified Information Systems Auditor Exam For getting Certified Information Systems Auditor (CISA) Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISACA. Trademarks, certification & product names are used for reference only and belong to ISACA. The website does not contain actual questions and answers from ISACA's Certification Exams.
Please login or Register to submit your answer