nerdexam
PeopleCert

ITIL · Question #354

Ensuring that the confidentiality, integrity and availability of the services are maintained to the levels agreed on the Service Level Agreement (SLA) is the responsibility of which role?

The correct answer is D. The Information Security Manager. The Information Security Manager owns the responsibility for maintaining confidentiality, integrity, and availability (CIA) of services to levels agreed in the SLA.

Roles

Question

Ensuring that the confidentiality, integrity and availability of the services are maintained to the levels agreed on the Service Level Agreement (SLA) is the responsibility of which role?

Options

  • AThe Service Level Manager
  • BThe Configuration Manager
  • CThe Change Manager
  • DThe Information Security Manager

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    92% (47)

Why each option

The Information Security Manager owns the responsibility for maintaining confidentiality, integrity, and availability (CIA) of services to levels agreed in the SLA.

AThe Service Level Manager

The Service Level Manager negotiates and monitors SLA performance targets but is not accountable for the security controls that enforce CIA of services.

BThe Configuration Manager

The Configuration Manager maintains the CMDB and manages configuration item records, which has no direct responsibility over security objectives like confidentiality or integrity.

CThe Change Manager

The Change Manager oversees the change management process to minimize risk from changes, not for governing or maintaining CIA security properties of services.

DThe Information Security ManagerCorrect

The Information Security Manager is specifically accountable for defining and governing security controls that uphold the CIA triad across services. This role ensures that security policies and controls maintain service confidentiality, integrity, and availability in alignment with SLA commitments - making it the designated owner of this responsibility within the ITIL framework.

Concept tested: ITIL Information Security Manager CIA triad responsibility

Topics

#Information Security Manager#Information Security Management#CIA triad

Community Discussion

No community discussion yet for this question.

Full ITIL Practice