ITIL-FOUNDATION · Question #533
Access management is responsible for implementing policies defined in which process?
The correct answer is B. Information security management. Access management implements the access control policies that are defined and owned by the Information Security Management process.
Question
Access management is responsible for implementing policies defined in which process?
Options
- AService portfolio management
- BInformation security management
- CChange management
- DProblem management
How the community answered
(41 responses)- A5% (2)
- B90% (37)
- C2% (1)
- D2% (1)
Why each option
Access management implements the access control policies that are defined and owned by the Information Security Management process.
Service Portfolio Management governs which services are offered and their investment lifecycle; it does not define access control or security policies.
Information Security Management is responsible for defining, maintaining, and communicating security policies - including who is authorized to access which services and data. Access Management then operationalizes those policies by granting, modifying, and revoking access rights to ensure only authorized users can use services.
Change Management controls the lifecycle of changes to IT infrastructure and services; it does not author or own information security access policies.
Problem Management focuses on identifying and eliminating root causes of incidents; it has no role in defining or enforcing access control policies.
Concept tested: ITIL Access Management relationship with Information Security Management
Source: https://www.axelos.com/certifications/itil-service-management/itil-4-foundation
Topics
Community Discussion
No community discussion yet for this question.