nerdexam
EXIN

ITSM20F · Question #73

Which statement with regard to Information Security Management is true?

The correct answer is B. Management with appropriate authority shall approve an Information Security policy. Option B is correct because information security governance standards (such as ISO/IEC 27001) require that an Information Security policy be formally approved by management with appropriate authority - this ensures accountability, executive sponsorship, and organizational…

Service delivery processes

Question

Which statement with regard to Information Security Management is true?

Options

  • AInformation Security Management to specifically focus on managing Information Security
  • BManagement with appropriate authority shall approve an Information Security policy.
  • CSecurity Incidents need to be reported and recorded immediately in line with the Problem
  • DSecurity Incidents shall only be reported and recorded if they affect more than one user

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    91% (31)
  • C
    6% (2)

Explanation

Option B is correct because information security governance standards (such as ISO/IEC 27001) require that an Information Security policy be formally approved by management with appropriate authority - this ensures accountability, executive sponsorship, and organizational commitment to security.

Why the distractors are wrong:

  • A is grammatically incomplete and misleading - ISM doesn't "specifically focus" on a narrow slice; it encompasses a broad framework of policies, controls, and governance.
  • C confuses two ITIL disciplines - Security Incidents follow the Incident Management process, not the Problem Management process, which deals with root causes of recurring issues.
  • D is false - all security incidents must be reported and recorded regardless of how many users are affected; a single-user breach can still represent a critical threat.

Memory tip: Think of the acronym MAP - Management must Approve the Policy. If a security policy lacks management sign-off, it has no organizational authority behind it.

Topics

#Information Security#security policy#management authority#ISM governance

Community Discussion

No community discussion yet for this question.

Full ITSM20F Practice