CAP · Question #186
Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not?
The correct answer is A. Auditor. An Auditor (A) is the person responsible for testing and verifying whether a security policy is properly implemented and whether the derived security solutions are adequate. Auditors independently assess security controls and configurations against defined policies and…
Question
Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not?
Options
- AAuditor
- BUser
- CData custodian
- DData owner
How the community answered
(14 responses)- A93% (13)
- B7% (1)
Explanation
An Auditor (A) is the person responsible for testing and verifying whether a security policy is properly implemented and whether the derived security solutions are adequate. Auditors independently assess security controls and configurations against defined policies and standards. A User interacts with the system but does not test security implementations. A Data Custodian manages and maintains data on behalf of the owner but does not audit policy compliance. A Data Owner defines classification and access policies but does not perform the technical verification - that is the auditor's role.
Topics
Community Discussion
No community discussion yet for this question.