nerdexam
(ISC)2

CAP · Question #186

Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not?

The correct answer is A. Auditor. An Auditor (A) is the person responsible for testing and verifying whether a security policy is properly implemented and whether the derived security solutions are adequate. Auditors independently assess security controls and configurations against defined policies and…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not?

Options

  • AAuditor
  • BUser
  • CData custodian
  • DData owner

How the community answered

(14 responses)
  • A
    93% (13)
  • B
    7% (1)

Explanation

An Auditor (A) is the person responsible for testing and verifying whether a security policy is properly implemented and whether the derived security solutions are adequate. Auditors independently assess security controls and configurations against defined policies and standards. A User interacts with the system but does not test security implementations. A Data Custodian manages and maintains data on behalf of the owner but does not audit policy compliance. A Data Owner defines classification and access policies but does not perform the technical verification - that is the auditor's role.

Topics

#Auditor responsibilities#Security policy verification#Control assessment#Roles and responsibilities

Community Discussion

No community discussion yet for this question.

Full CAP Practice