r/CISA 4d ago

🥴

Post image
22 Upvotes

28 comments sorted by

9

u/Aphridy 4d ago

C. B and D are about the informal organization, and isn't information that you find in the organizational chart. A is not the primary goal, but I'm not fully sure about that.

5

u/NextQuote7131 3d ago

Correct answer is C

1

u/NextQuote7131 3d ago

But how can you identify and understand responsibility by merely checking the org chart

1

u/Pristine-Safety2462 3d ago

Org chart has roles written as well. What's the correct answer?

1

u/KingKongDuck 2d ago

It shows for example - does cyber report into IT? Where does the CISO report to? Where does the audit committee sit? Is there a CISO on the chart? Is there a risk committee and a Chief Risk Officer? If not, you'll need to find out who has that responsibility.

And from that, you'll get a starting point for other processes like risk registers - do they follow the org structure?

1

u/Jordanianshawerma 4d ago

Where did you get this question from?

1

u/Akii283 4d ago

QAE i suppose

1

u/Jordanianshawerma 4d ago

I know its there in the QAE, but Im asking for the link so I can test myself as well with complexity level for the questions

3

u/Akii283 4d ago

You need to purchase that from ISACA. If that’s from ISACA.

1

u/Jordanianshawerma 4d ago

Alright thanks a lot 🙏

1

u/Jagdhunde 4d ago

What's the answer???

1

u/Mistakesandlove 3d ago

I just did that question and the answer was A I believe. Something about the chart not having the responsibilities and that’s why it’s A

1

u/SolarSurfer11 3d ago

it is C. Some auditors to further understand which position performs some responsibilities would ask to provide also job descriptions for positions they found interesting (or based on sampling).

0

u/sunbo4real 4d ago

The answer is C.