CISA · Question #646
An organization-wide review shows poor employee adherence to IT access control policies. Which of the following is PRIMARILY responsible for establishing the appropriate control culture?
The correct answer is D. Senior leadership. Organizational culture - including a culture of compliance and controls - flows from the top down. Senior leadership sets the tone by visibly championing policies, allocating resources, and enforcing accountability. When adherence is poor organization-wide, it reflects a failure
Question
An organization-wide review shows poor employee adherence to IT access control policies. Which of the following is PRIMARILY responsible for establishing the appropriate control culture?
Options
- ASystem users
- BIS audit department
- CInformation security department
- DSenior leadership
How the community answered
(32 responses)- A6% (2)
- C3% (1)
- D91% (29)
Explanation
Organizational culture - including a culture of compliance and controls - flows from the top down. Senior leadership sets the tone by visibly championing policies, allocating resources, and enforcing accountability. When adherence is poor organization-wide, it reflects a failure of leadership to embed controls into the culture, not just a technical or departmental issue. System users (A) are responsible for following policies, not establishing culture. IS audit (B) assesses and advises but does not set culture. Information security (C) designs and enforces controls but lacks the organizational authority to drive culture change without executive sponsorship.
Topics
Community Discussion
No community discussion yet for this question.