🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor100 / 148
Question 100 of 148

During a governance review, an IS auditor finds that the organization's information security policies were last approved five years ago. Since then, the company has adopted cloud services, a remote-work model, and is now subject to new data protection regulations. Management states the policies are still 'technically valid.' What should the auditor conclude is the MOST significant governance weakness?

Reviewed for accuracy · Report an issueNext question