Question 106

An auditor is reviewing an organization's virtual machines (VMs) hosted in the cloud. The organization utilizes a configuration management (CM) tool to enforce password policies on its VMs. Which of the following is the BEST approach for the auditor to use to review the operating effectiveness of the password requirement?
  • Question 107

    An organization currently following the ISO/IEC 27002 control framework has been charged by a new CIO to switch to the NIST 800-53 control framework. Which of the following is the FIRST step to this change?
  • Question 108

    If the degree of verification for information shared with the auditor during an audit is low, the auditor should:
  • Question 109

    Which of the following is the reason for designing the Consensus Assessments Initiative Questionnaire (CAIQ)?
  • Question 110

    organization should document the compliance responsibilities and ownership of accountability in a RACI chart or its informational equivalents in order to: