CISM · Question #129
Which of the following should an information security manager establish FIRST to ensure security-related activities are adequately monitored?
The correct answer is B. Accountability for security functions. To ensure security activities are adequately monitored, an information security manager should first establish accountability for security functions, clarifying who is responsible for what.
Question
Which of the following should an information security manager establish FIRST to ensure security-related activities are adequately monitored?
Options
- ARegular reviews of system logs
- BAccountability for security functions
- CProcedures for security assessments
- DSchedules for internal audits
How the community answered
(32 responses)- A6% (2)
- B72% (23)
- C3% (1)
- D19% (6)
Why each option
To ensure security activities are adequately monitored, an information security manager should first establish accountability for security functions, clarifying who is responsible for what.
Regular reviews of system logs are a monitoring *activity*, but they cannot be adequately performed or acted upon without established accountability.
Establishing clear accountability means assigning specific individuals or teams ownership for various security functions and their monitoring, ensuring that there is a responsible party to oversee and address security-related activities. Without clear accountability, monitoring mechanisms like log reviews or audits may be performed without clear ownership or follow-up, leading to inefficiencies or gaps.
Procedures for security assessments define *how* assessments are done, but accountability determines *who* initiates, oversees, and responds to them.
Schedules for internal audits are a part of monitoring, but accountability defines who is responsible for conducting the audits and addressing their findings.
Concept tested: Information security governance - accountability
Topics
Community Discussion
No community discussion yet for this question.