nerdexam
(ISC)2

CSSLP · Question #16

Which of the following individuals inspects whether the security policies, standards, guidelines, and procedures are efficiently performed in accordance with the company's stated security objectives?

The correct answer is D. Information system auditor. An Information System Auditor is the individual primarily responsible for independently inspecting and evaluating whether an organization's security policies, standards, guidelines, and procedures are efficiently and effectively implemented and comply with stated security objecti

Secure Software Lifecycle Management

Question

Which of the following individuals inspects whether the security policies, standards, guidelines, and procedures are efficiently performed in accordance with the company's stated security objectives?

Options

  • AInformation system security professional
  • BData owner
  • CSenior management
  • DInformation system auditor

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    90% (43)

Why each option

An Information System Auditor is the individual primarily responsible for independently inspecting and evaluating whether an organization's security policies, standards, guidelines, and procedures are efficiently and effectively implemented and comply with stated security objectives.

AInformation system security professional

An Information System Security Professional is responsible for implementing, managing, and maintaining security controls, not primarily for independent inspection and auditing.

BData owner

A Data Owner is typically responsible for classifying and protecting specific data, delegating its management, but not for auditing the overall security program across systems.

CSenior management

Senior Management is responsible for setting the overall strategic direction for security and ensuring resources are available, but they do not typically perform the detailed, independent inspection of security control performance.

DInformation system auditorCorrect

An Information System Auditor's role is specifically to provide independent assurance that an organization's information systems and related processes, including security policies, standards, and procedures, are properly designed and operating effectively. Their function involves detailed inspection and evaluation against established objectives and compliance frameworks, ensuring that security controls are being efficiently performed and meeting company security goals.

Concept tested: Roles and responsibilities in information security

Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final

Topics

#Security Roles#Audit#Compliance#Governance

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice