ITIL · Question #354
Ensuring that the confidentiality, integrity and availability of the services are maintained to the levels agreed on the Service Level Agreement (SLA) is the responsibility of which role?
The correct answer is D. The Information Security Manager. The Information Security Manager owns the responsibility for maintaining confidentiality, integrity, and availability (CIA) of services to levels agreed in the SLA.
Question
Ensuring that the confidentiality, integrity and availability of the services are maintained to the levels agreed on the Service Level Agreement (SLA) is the responsibility of which role?
Options
- AThe Service Level Manager
- BThe Configuration Manager
- CThe Change Manager
- DThe Information Security Manager
How the community answered
(51 responses)- A2% (1)
- B2% (1)
- C4% (2)
- D92% (47)
Why each option
The Information Security Manager owns the responsibility for maintaining confidentiality, integrity, and availability (CIA) of services to levels agreed in the SLA.
The Service Level Manager negotiates and monitors SLA performance targets but is not accountable for the security controls that enforce CIA of services.
The Configuration Manager maintains the CMDB and manages configuration item records, which has no direct responsibility over security objectives like confidentiality or integrity.
The Change Manager oversees the change management process to minimize risk from changes, not for governing or maintaining CIA security properties of services.
The Information Security Manager is specifically accountable for defining and governing security controls that uphold the CIA triad across services. This role ensures that security policies and controls maintain service confidentiality, integrity, and availability in alignment with SLA commitments - making it the designated owner of this responsibility within the ITIL framework.
Concept tested: ITIL Information Security Manager CIA triad responsibility
Topics
Community Discussion
No community discussion yet for this question.