nerdexam
(ISC)2

CGRC · Question #193

Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not? Response:

The correct answer is A. Auditor. The auditor is responsible for independently assessing and verifying the implementation and effectiveness of security policies and solutions within an organization.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following persons is responsible for testing and verifying whether the security policy is properly implemented, and the derived security solutions are adequate or not? Response:

Options

  • AAuditor
  • BUser
  • CData custodian
  • DData owner

How the community answered

(16 responses)
  • A
    88% (14)
  • B
    6% (1)
  • D
    6% (1)

Why each option

The auditor is responsible for independently assessing and verifying the implementation and effectiveness of security policies and solutions within an organization.

AAuditorCorrect

An auditor's primary role is to conduct independent assessments and examinations of an organization's systems, processes, and controls to determine compliance with policies, standards, and regulations. This includes testing and verifying the proper implementation of security policies and the adequacy of security solutions to identify any gaps or deficiencies.

BUser

A user is an end-consumer of the system and is not typically responsible for auditing its security.

CData custodian

A data custodian is responsible for the technical implementation and maintenance of security controls for data, not for independent verification.

DData owner

A data owner is responsible for the overall classification, protection, and risk acceptance for data, but does not typically perform the auditing function.

Concept tested: Roles and responsibilities in IT security

Source: https://csrc.nist.gov/glossary/term/auditor

Topics

#Auditor role#Security policy verification#Control assessment#Compliance checking

Community Discussion

No community discussion yet for this question.

Full CGRC Practice