CSSLP · Question #16
Which of the following individuals inspects whether the security policies, standards, guidelines, and procedures are efficiently performed in accordance with the company's stated security objectives?
The correct answer is D. Information system auditor. An Information System Auditor is the individual primarily responsible for independently inspecting and evaluating whether an organization's security policies, standards, guidelines, and procedures are efficiently and effectively implemented and comply with stated security objecti
Question
Which of the following individuals inspects whether the security policies, standards, guidelines, and procedures are efficiently performed in accordance with the company's stated security objectives?
Options
- AInformation system security professional
- BData owner
- CSenior management
- DInformation system auditor
How the community answered
(48 responses)- A6% (3)
- B2% (1)
- C2% (1)
- D90% (43)
Why each option
An Information System Auditor is the individual primarily responsible for independently inspecting and evaluating whether an organization's security policies, standards, guidelines, and procedures are efficiently and effectively implemented and comply with stated security objectives.
An Information System Security Professional is responsible for implementing, managing, and maintaining security controls, not primarily for independent inspection and auditing.
A Data Owner is typically responsible for classifying and protecting specific data, delegating its management, but not for auditing the overall security program across systems.
Senior Management is responsible for setting the overall strategic direction for security and ensuring resources are available, but they do not typically perform the detailed, independent inspection of security control performance.
An Information System Auditor's role is specifically to provide independent assurance that an organization's information systems and related processes, including security policies, standards, and procedures, are properly designed and operating effectively. Their function involves detailed inspection and evaluation against established objectives and compliance frameworks, ensuring that security controls are being efficiently performed and meeting company security goals.
Concept tested: Roles and responsibilities in information security
Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.