A Chief Information Security Officer would like to conduct frequent, detailed reviews of systems and procedures to track compliance objectives. Which of the following will be the best method to achieve this objective?
Choose an answer
Tap an option to check your answer.
Correct answer: Internal auditing.
Why this is the answer
Internal auditing is the best method because it involves a systematic, independent examination of an organization's operations, controls, and compliance with policies, procedures, and regulations. This process allows for frequent, detailed reviews to track compliance objectives directly. Third-party attestation involves an external party providing an opinion on an organization's controls, which is less frequent and detailed than internal auditing. Penetration testing focuses on identifying exploitable vulnerabilities rather than comprehensive compliance tracking. Vulnerability scans identify security weaknesses but do not provide the detailed procedural and systemic review needed for compliance objectives.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed