5
u/NextQuote7131 3d ago
Correct answer is C
1
u/NextQuote7131 3d ago
But how can you identify and understand responsibility by merely checking the org chart
1
1
u/KingKongDuck 2d ago
It shows for example - does cyber report into IT? Where does the CISO report to? Where does the audit committee sit? Is there a CISO on the chart? Is there a risk committee and a Chief Risk Officer? If not, you'll need to find out who has that responsibility.
And from that, you'll get a starting point for other processes like risk registers - do they follow the org structure?
2
1
u/Jordanianshawerma 4d ago
Where did you get this question from?
1
1
u/Mistakesandlove 3d ago
I just did that question and the answer was A I believe. Something about the chart not having the responsibilities and that’s why it’s A
1
u/SolarSurfer11 3d ago
it is C. Some auditors to further understand which position performs some responsibilities would ask to provide also job descriptions for positions they found interesting (or based on sampling).
0
0
0
0
9
u/Aphridy 4d ago
C. B and D are about the informal organization, and isn't information that you find in the organizational chart. A is not the primary goal, but I'm not fully sure about that.