SSCP · Question #1143
What are the main goals of an information security program? (Choose all that apply)
The correct answer is B. Confidentiality C. Availability D. Integrity of data. The main goals of an information security program are to ensure the Confidentiality, Integrity, and Availability (CIA triad) of data and systems.
Question
What are the main goals of an information security program? (Choose all that apply)
Options
- AComplete Security
- BConfidentiality
- CAvailability
- DIntegrity of data
- EEase of Use
How the community answered
(29 responses)- A3% (1)
- B93% (27)
- E3% (1)
Why each option
The main goals of an information security program are to ensure the Confidentiality, Integrity, and Availability (CIA triad) of data and systems.
Complete Security is an unachievable goal in information security, as all risks cannot be entirely eliminated.
Confidentiality ensures that information is accessible only to authorized individuals, protecting it from unauthorized disclosure.
Availability ensures that authorized users can access information and resources when they are needed, preventing disruption of services.
Integrity of data ensures that information remains accurate, complete, and protected from unauthorized modification or destruction.
While ease of use is a desirable design principle, it is a secondary consideration often balanced against security requirements and is not one of the fundamental pillars of information security itself.
Concept tested: CIA triad (Confidentiality, Integrity, Availability)
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/confidentiality-integrity-availability
Topics
Community Discussion
No community discussion yet for this question.