ITIL-FOUNDATION · Question #25
Which process is responsible for the availability, confidentiality and integrity of data?
The correct answer is D. Information security management. Information security management owns the CIA triad - Confidentiality, Integrity, and Availability - for all information assets across the organization.
Question
Which process is responsible for the availability, confidentiality and integrity of data?
Options
- AService catalogue management
- BService asset and configuration management
- CChange management
- DInformation security management
How the community answered
(33 responses)- B6% (2)
- C3% (1)
- D91% (30)
Why each option
Information security management owns the CIA triad - Confidentiality, Integrity, and Availability - for all information assets across the organization.
Service catalogue management maintains records of live IT services and their details, but has no responsibility for data security properties.
Service asset and configuration management tracks CIs and their relationships but does not govern security attributes like confidentiality or integrity.
Change management controls the lifecycle of changes to reduce risk, but it does not own or enforce the CIA triad for data.
Information security management is the ITIL process explicitly chartered to protect the confidentiality, integrity, and availability (CIA) of an organization's information assets. It defines security policies, manages security controls, and ensures data is accessible only to authorized parties while remaining accurate and available when needed.
Concept tested: ITIL information security management CIA triad ownership
Source: https://www.axelos.com/certifications/itil-service-management/itil-4-foundation
Topics
Community Discussion
No community discussion yet for this question.