CISA Certified Information Systems Auditor – Question0627

A business unit uses an e-commerce application with a strong password policy. Many customers complain that they cannot remember their passwords because they are too long and complex. The business unit states it is imperative to improve the customer experience. The information security manager should FIRST:

A.
change the password policy to improve the customer experience.
B. recommend implementing two-factor authentication.
C. research alternative secure methods of identity verification.
D. evaluate the impact of the customer’s experience on business revenue.

Correct Answer: C