IS 監査人が組織のサイバーセキュリティ インシデント対応の成熟度のレビューを計画しています。次の方法のうち、最も信頼性の高い結論を提供するものはどれでしょうか。
正解:D
Compliance testing ensures that the organization's incident response processes align with established cybersecurity frameworks and policies. This methodology provides objective and reliable conclusions about the maturity of incident response capabilities. * Judgmental Sampling (Option A):Relies on subjective judgment and is less reliable. * Data Analytics Testing (Option B):Useful for identifying trends but may not assess process maturity comprehensively. * Variable Sampling (Option C):Appropriate for statistical analysis but less effective in process maturity assessments. Reference:ISACA CISA Review Manual, Job Practice Area 2: Information Systems Audit and Assurance.