nerdexam
(ISC)2

SSCP · Question #206

Who is ultimately responsible for the security of computer based information systems within an organization?

The correct answer is C. The management team. If there is no support by management to implement, execute, and enforce security policies and procedure, then they won't work. Senior management must be involved in this because they have an obligation to the organization to protect the assests . The requirement here is for…

Submitted by luis.pe· Apr 18, 2026Security Concepts and Practices

Question

Who is ultimately responsible for the security of computer based information systems within an organization?

Options

  • AThe tech support team
  • BThe Operation Team.
  • CThe management team.
  • DThe training team.

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    92% (49)
  • D
    2% (1)

Explanation

If there is no support by management to implement, execute, and enforce security policies and procedure, then they won't work. Senior management must be involved in this because they have an obligation to the organization to protect the assests . The requirement here is for management to show "due diligence" in establishing an effective compliance, or security program. The following answers are incorrect: The tech support team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems. The Operation Team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems. The Training Team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems.

Topics

#Security governance#Management accountability#Organizational responsibility#Information security leadership

Community Discussion

No community discussion yet for this question.

Full SSCP Practice