712-50 · Question #332
Which of the following are not stakeholders of IT security projects?
The correct answer is B. Third party vendors. Third-party vendors are generally considered external parties rather than internal project stakeholders. In the context of IT security projects, stakeholders are typically defined as those within the organization who have a direct interest in, authority over, or are impacted by…
Question
Which of the following are not stakeholders of IT security projects?
Options
- ABoard of directors
- BThird party vendors
- CCISO
- DHelp Desk
How the community answered
(20 responses)- A15% (3)
- B70% (14)
- C5% (1)
- D10% (2)
Explanation
Third-party vendors are generally considered external parties rather than internal project stakeholders. In the context of IT security projects, stakeholders are typically defined as those within the organization who have a direct interest in, authority over, or are impacted by security outcomes - vendors, by contrast, are subject to security requirements but do not own or govern the security program itself.
Why the distractors are wrong:
- A (Board of Directors): Executives are primary stakeholders - they hold ultimate accountability for organizational risk and approve security budgets and policy.
- C (CISO): The Chief Information Security Officer is the most directly responsible stakeholder, owning the security strategy and program.
- D (Help Desk): Often overlooked, but Help Desk staff are frontline stakeholders - they enforce access policies, handle security incidents, and are affected daily by security procedures.
Memory tip: Think of stakeholders as anyone inside the organization with skin in the game - from the boardroom (governance) to the Help Desk (operations). Vendors sit outside that boundary; your organization manages them through contracts and controls, not as co-owners of the security program. If you can fire someone or override their security decisions internally, they're likely a stakeholder.
Topics
Community Discussion
No community discussion yet for this question.