nerdexam
(ISC)2

CGRC · Question #207

The system authorization program often fails due to failure to separate and assign duties at the system level, poor planning, poor systems inventory and many other reasons including which of the…

The correct answer is B. Lack of management support. The question asks for another common reason why system authorization programs fail, beyond those already listed.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The system authorization program often fails due to failure to separate and assign duties at the system level, poor planning, poor systems inventory and many other reasons including which of the following? Response:

Options

  • AInability to work with remote teams.
  • BLack of management support.
  • CLack of project management office.
  • DInsufficient system rights.

How the community answered

(32 responses)
  • B
    94% (30)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The question asks for another common reason why system authorization programs fail, beyond those already listed.

AInability to work with remote teams.

While managing remote teams can present challenges, it is not a fundamental, overarching reason for the failure of an entire system authorization program itself.

BLack of management support.Correct

A critical and common reason for the failure of a system authorization program is a lack of management support, as this undermines the allocation of necessary resources, proper prioritization, and the enforcement of security policies and requirements across the organization.

CLack of project management office.

The absence of a Project Management Office (PMO) can hinder project execution, but it's not as direct a cause for authorization program failure as a lack of senior management commitment.

DInsufficient system rights.

Insufficient system rights refers to access control issues for users or systems, which is a detailed technical control problem, not a primary cause for the breakdown of the entire authorization program.

Concept tested: Critical success factors for IT security programs

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Management support#Program effectiveness#Authorization program#Governance issues

Community Discussion

No community discussion yet for this question.

Full CGRC Practice