CISA-KR 문제 401
CISA-KR 문제 402
Business owners are the individuals or entities who have the authority and responsibility to define the business needs and expectations for the project. They are also the primary beneficiaries of the project outcomes and benefits. Business owners play a crucial role in the project initiation phase, as they provide valuable input and feedback on the requirements and specifications of the project. Requirements are the statements that describe what the project should accomplish or deliver to meet the business needs and expectations. Requirements are essential for guiding the project planning, execution, monitoring, and closure phases.
If business owners are removed from the project initiation phase, it can result in incomplete or inaccurate requirements, which can have negative impacts on the project's quality, scope, time, cost, and risk. Some of the possible consequences of incomplete requirements are:
Misalignment: The project may not align with the business strategy, vision, or goals, which can reduce its value or relevance.
Confusion: The project team may not have a clear understanding of what the project should achieve or deliver, which can affect their performance or productivity.
Rework: The project may need to undergo frequent changes or revisions to accommodate new or modified requirements, which can increase the time and cost of the project.
Dissatisfaction: The project may not meet the expectations or satisfaction of the business owners or other stakeholders, which can affect their acceptance or support of the project.
Failure: The project may not deliver the expected outcomes or benefits, which can affect its success or viability.
Therefore, an IS auditor should be concerned about the involvement and participation of business owners in the project initiation phase, as it affects the completeness and quality of requirements. An IS auditor should review the policies and procedures for stakeholder identification and engagement, verify that the business owners have adequate knowledge and skills to define their requirements, and test that the requirements are well-defined, documented, approved, and communicated.
References:
Project Initiation: The First Step to Project Management [2023] * Asana Everything you need to know about the project initiation phase Project Initiation Phase - The Business Professor Project Initiation: A Guide to Starting a Project Right Way - Kissflow
CISA-KR 문제 403
CISA-KR 문제 404
One of the key aspects of change management is measuring its effectiveness, which means assessing whether the changes have achieved the desired outcomes and met the expectations of the stakeholders. There are various indicators that can be used to measure change management effectiveness, such as time, cost, quality, scope, satisfaction, and performance.
Among the four options given, the most appropriate indicator of change management effectiveness is the number of incidents resulting from changes. An incident is an unplanned event or interruption that affects the normal operation or service delivery of an information system. Incidents can be caused by various factors, such as errors, defects, failures, malfunctions, or malicious attacks. Incidents can have negative impacts on the organization, such as loss of data, productivity, reputation, or revenue.
The number of incidents resulting from changes is a direct measure of how well the changes have been planned, implemented, monitored, and evaluated. A high number of incidents indicates that the changes have not been properly tested, verified, communicated, or controlled. A low number of incidents indicates that the changes have been executed smoothly and successfully. Therefore, the number of incidents resulting from changes reflects the quality and effectiveness of the change management process.
The other three options are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes. The time lag between changes to the configuration and the update of records is a measure of how timely and accurate the configuration management process is. Configuration management is a subset of change management that focuses on identifying, documenting, and controlling the configuration items (CIs) that make up an information system. The time lag between changes and updates of documentation materials is a measure of how well the documentation process is aligned with the change management process. Documentation is an important aspect of change management that provides information and guidance to the stakeholders involved in or affected by the changes. The number of system software changes is a measure of how frequently and extensively the system software is modified or updated. System software changes are a type of change that affects the operating system, middleware, or utilities that support an information system.
While these three indicators are relevant and useful for measuring certain aspects of change management, they do not directly measure the outcomes or impacts of the changes on the organization. They are more related to the inputs or activities of change management than to its outputs or results. Therefore, they are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes.
References:
Metrics for Measuring Change Management - Prosci
How to Measure Change Management Effectiveness: Metrics, Tools & Processes Metrics for Measuring Change Management 2023 - Zendesk
CISA-KR 문제 405
When verifying the integrity of a bit-for-bit copy of digital evidence, hashing algorithms are used. The primary factors in selecting a hashing algorithm are speed and collision resistance.
* MD5 (Message Digest 5): While not cryptographically secure for all modern applications due to collision vulnerabilities, it is very fast and still acceptable in forensic integrity verification where speed is critical and the probability of collision is negligible for one-time checks.
* SHA-1 / SHA-2: Provide stronger cryptographic assurance but are slower than MD5. They are preferred for long-term integrity assurance but not when processing speed is the top priority.
* AES (Advanced Encryption Standard): AES is an encryption algorithm, not a hashing algorithm, and therefore is not appropriate for integrity verification.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 5 (Protection of Information Assets), section on cryptographic controls for evidence integrity.
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4214ISACA.CISA-KR.v2026-05-16.q709
- 1826ISACA.CISA-KR.v2026-05-06.q261
- 3193ISACA.CISA-KR.v2026-03-16.q665
- 9343ISACA.CISA-KR.v2025-04-07.q633
- 4491ISACA.CISA-KR.v2025-04-03.q628
- 3737ISACA.CISA-KR.v2025-04-02.q544
- 4280ISACA.CISA-KR.v2025-03-31.q534
- 5432ISACA.CISA-KR.v2025-03-28.q617
- 3255ISACA.CISA-KR.v2025-03-19.q581
- 4059ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5389ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 167Microsoft.MS-700-KR.v2026-08-15.q203
- 131Microsoft.AZ-305-KR.v2026-08-14.q177
- 190Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 219Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
