nerdexam
Isaca

CGEIT · Question #127

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

The correct answer is A. Authenticating access to information assets based on roles or business rules. To address privacy noncompliance and ensure appropriate ownership of access controls, it is most important to authenticate access based on defined roles or business rules, which establishes clear responsibility for who can access what.

Submitted by lars.no· Apr 18, 2026Governance of Enterprise IT

Question

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

Options

  • AAuthenticating access to information assets based on roles or business rules.
  • BImplementing multi-factor authentication controls
  • CGranting access to information based on information architecture
  • DEngaging an audit of logical access controls and related security policies

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    14% (4)
  • C
    3% (1)
  • D
    7% (2)

Why each option

To address privacy noncompliance and ensure appropriate ownership of access controls, it is most important to authenticate access based on defined roles or business rules, which establishes clear responsibility for who can access what.

AAuthenticating access to information assets based on roles or business rules.Correct

Implementing access controls based on roles or business rules ensures that individuals are granted access commensurate with their job function and the principle of least privilege, thereby defining the 'owner' of that access entitlement. This systematic approach directly links access privileges to specific organizational functions, which is crucial for demonstrating compliance with privacy regulations by limiting access to personal data to only those who require it for legitimate business purposes.

BImplementing multi-factor authentication controls

Implementing multi-factor authentication enhances the strength of authentication but does not inherently address the ownership or appropriateness of what a user can access once authenticated.

CGranting access to information based on information architecture

Granting access based on information architecture describes how data is structured, but it doesn't establish the ownership or business justification for who should have access.

DEngaging an audit of logical access controls and related security policies

Engaging an audit is a verification step to assess existing controls and policies, but it's not the primary action to establish appropriate ownership of access controls in the first place.

Concept tested: Role-based access control and ownership

Source: https://learn.microsoft.com/en-us/azure/role-based-access-control/overview

Topics

#Access Control Ownership#Privacy Compliance#Role-Based Access Control#IT Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice