ITSM20F · Question #31
What is the objective of the Security Management process?
The correct answer is D. to manage information security effectively within all service activities. Security Management aims to protect all service activities - covering people, processes, and technology across the entire organization - which is why D is correct. Limiting scope to critical services (A), IT staff only (B), or financial administration (C) each represent partial c
Question
What is the objective of the Security Management process?
Options
- Ato manage information security effectively for critical services only
- Bto manage information security effectively for IT staff
- Cto manage information security effectively relating to the financial administration of service
- Dto manage information security effectively within all service activities
How the community answered
(30 responses)- A3% (1)
- B7% (2)
- C7% (2)
- D83% (25)
Explanation
Security Management aims to protect all service activities - covering people, processes, and technology across the entire organization - which is why D is correct. Limiting scope to critical services (A), IT staff only (B), or financial administration (C) each represent partial coverage, and security gaps arise precisely where scope is narrowed. The ITIL Security Management process is explicitly designed to align with business-wide security requirements, not any single department or service tier.
Memory tip: Think "Security has no exceptions" - if the answer restricts who or what is protected, it's wrong. The word all in option D is the signal that matches the process's universal scope.
Topics
Community Discussion
No community discussion yet for this question.