nerdexam
EC-Council

712-50 · Question #332

Which of the following are not stakeholders of IT security projects?

The correct answer is B. Third party vendors. Third-party vendors are generally considered external parties rather than internal project stakeholders. In the context of IT security projects, stakeholders are typically defined as those within the organization who have a direct interest in, authority over, or are impacted by…

Security Program Management & Operations

Question

Which of the following are not stakeholders of IT security projects?

Options

  • ABoard of directors
  • BThird party vendors
  • CCISO
  • DHelp Desk

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    70% (14)
  • C
    5% (1)
  • D
    10% (2)

Explanation

Third-party vendors are generally considered external parties rather than internal project stakeholders. In the context of IT security projects, stakeholders are typically defined as those within the organization who have a direct interest in, authority over, or are impacted by security outcomes - vendors, by contrast, are subject to security requirements but do not own or govern the security program itself.

Why the distractors are wrong:

  • A (Board of Directors): Executives are primary stakeholders - they hold ultimate accountability for organizational risk and approve security budgets and policy.
  • C (CISO): The Chief Information Security Officer is the most directly responsible stakeholder, owning the security strategy and program.
  • D (Help Desk): Often overlooked, but Help Desk staff are frontline stakeholders - they enforce access policies, handle security incidents, and are affected daily by security procedures.

Memory tip: Think of stakeholders as anyone inside the organization with skin in the game - from the boardroom (governance) to the Help Desk (operations). Vendors sit outside that boundary; your organization manages them through contracts and controls, not as co-owners of the security program. If you can fire someone or override their security decisions internally, they're likely a stakeholder.

Topics

#stakeholder management#IT security governance#project management#organizational structure

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice