ITIL-FOUNDATION · Question #310
Which of the following defines the level of protection in Information Security Management?
The correct answer is C. The Business. In Information Security Management, the business defines the required level of protection because it owns the assets and sets the risk appetite.
Question
Which of the following defines the level of protection in Information Security Management?
Options
- AThe IT Executive
- BThe ISO27001 Standard
- CThe Business
- DThe Service Level Manager
How the community answered
(26 responses)- A4% (1)
- C88% (23)
- D8% (2)
Why each option
In Information Security Management, the business defines the required level of protection because it owns the assets and sets the risk appetite.
The IT Executive is responsible for implementing security decisions, not for defining the protection level required by the organization.
ISO 27001 provides a framework and set of controls for information security, but it does not determine what level of protection a specific organization requires - the business does.
The business is responsible for defining what level of protection is required for its information assets, because it understands the value of those assets and the acceptable level of risk. IT and security functions implement and enforce the controls, but the authority and accountability for protection requirements rests with the business. This is a core principle in ITIL Information Security Management and ISO 27001.
The Service Level Manager negotiates and manages service agreements, but has no authority to define information security protection levels.
Concept tested: Business ownership of information security protection levels
Source: https://www.iso.org/standard/27001
Topics
Community Discussion
No community discussion yet for this question.