Laws and regulations are being enacted with the aim of protecting the interests of stakeholders. In the field of IT, the most common objectives of laws and regulations include the safeguarding of privacy and the confidentiality of personal data, the protection of intellectual property rights, and the integrity of financial information.
All these laws and regulations mandate various policies and procedures to protect the interests of stakeholders. CISA aspirants should be aware that there will be no direct questions in the exam on any of the particular laws or regulations.
An IS auditor's role in determining adherence to laws and regulations
An IS auditor should consider the following factors in determining the level of adherence to laws and regulations by an organization:
- Has an organization identified applicable laws and regulations pertaining to IT?
- How are the Governance, Risk, and Compliance (GRC) program implemented...