The Chief Information Security Officer (CISO) at a large company would like to gain an understanding of how the company's security policies compare to the requirements imposed by external regulators. Which of the following should the CISO use?
Choose an answer
Tap an option to check your answer.
Correct answer: Internal audit.
Why this is the answer
An internal audit is the most appropriate choice because it systematically evaluates an organization's internal controls, governance processes, and compliance with policies and external regulations. This directly addresses the CISO's need to understand how company policies align with regulatory requirements. A penetration test focuses on finding vulnerabilities by simulating an attack, not policy comparison. Attestation is a formal declaration or certification by a third party, often used to confirm compliance, but an internal audit is the process to determine that compliance. An external examination is similar to an external audit, performed by an independent third party, which could be used, but an internal audit is typically the first step to assess and ensure readiness before external scrutiny.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed