正解:C
The finding that should be of most concern to an IS auditor when evaluating information security governance within an organization is that the data center manager has final sign-off on security projects. This indicates a lack of segregation of duties and a potential conflict of interest between the operational and security roles. The data center manager may have access to sensitive information or systems that should be protected by security controls, or may influence or override security decisions that are not in the best interest of the organization.
This finding also suggests that there is no clear accountability or authority for information security governance at a higher level, such as seniormanagement or board of directors. The other findings are not as concerning as this one, although they may indicate some areas for improvement or monitoring. References:
* ISACA, CISA Review Manual, 27th Edition, chapter 5, section 5.11
* ISACA, IT Governance Using COBIT and Val IT: Student Booklet - 2nd Edition4