nerdexam
PeopleCert

ITIL-FOUNDATION · Question #310

Which of the following defines the level of protection in Information Security Management?

The correct answer is C. The Business. In Information Security Management, the business defines the required level of protection because it owns the assets and sets the risk appetite.

Know the purpose of the ITIL practices

Question

Which of the following defines the level of protection in Information Security Management?

Options

  • AThe IT Executive
  • BThe ISO27001 Standard
  • CThe Business
  • DThe Service Level Manager

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    88% (23)
  • D
    8% (2)

Why each option

In Information Security Management, the business defines the required level of protection because it owns the assets and sets the risk appetite.

AThe IT Executive

The IT Executive is responsible for implementing security decisions, not for defining the protection level required by the organization.

BThe ISO27001 Standard

ISO 27001 provides a framework and set of controls for information security, but it does not determine what level of protection a specific organization requires - the business does.

CThe BusinessCorrect

The business is responsible for defining what level of protection is required for its information assets, because it understands the value of those assets and the acceptable level of risk. IT and security functions implement and enforce the controls, but the authority and accountability for protection requirements rests with the business. This is a core principle in ITIL Information Security Management and ISO 27001.

DThe Service Level Manager

The Service Level Manager negotiates and manages service agreements, but has no authority to define information security protection levels.

Concept tested: Business ownership of information security protection levels

Source: https://www.iso.org/standard/27001

Topics

#information security management#security policy#business requirements#protection levels

Community Discussion

No community discussion yet for this question.

Full ITIL-FOUNDATION Practice