CGEIT · Question #583
From a governance perspective, which of the following functions MUST approve the agreed-upon criteria for a new technology-enabled service before submitting the final high-level design to project stak
The correct answer is A. Information security. From a governance perspective, information security is the function that must approve the agreed-upon criteria for a new technology-enabled service to ensure alignment with security requirements before the high-level design proceeds.
Question
From a governance perspective, which of the following functions MUST approve the agreed-upon criteria for a new technology-enabled service before submitting the final high-level design to project stakeholders?
Options
- AInformation security
- BProject management office (PMO)
- CQuality assurance (QA)
- DInternal audit
How the community answered
(62 responses)- A77% (48)
- B6% (4)
- C3% (2)
- D13% (8)
Why each option
From a governance perspective, information security is the function that *must* approve the agreed-upon criteria for a new technology-enabled service to ensure alignment with security requirements before the high-level design proceeds.
From a governance perspective, Information Security *must* approve the criteria for a new technology-enabled service at an early stage to ensure that security requirements are embedded by design and meet organizational policies and regulatory obligations. Neglecting this early approval can lead to costly redesigns, vulnerabilities, or non-compliance later in the development lifecycle. This is part of a "security by design" principle.
The Project Management Office (PMO) ensures adherence to project processes and methodology but is not primarily responsible for approving the *criteria* related to the fundamental security posture of the service itself.
Quality Assurance (QA) focuses on ensuring the service meets its functional and non-functional requirements and quality standards, but its primary role is not the initial approval of *security criteria*.
Internal Audit provides independent assurance over the effectiveness of governance, risk management, and control processes, typically reviewing *after* controls and criteria have been established and implemented, not approving initial criteria.
Concept tested: Governance of new service security criteria
Topics
Community Discussion
No community discussion yet for this question.