SSCP · Question #208
Which must bear the primary responsibility for determining the level of protection needed for information systems resources?
The correct answer is B. Senior Management. If there is no support by senior management to implement, execute, and enforce security policies and procedure, then they won't work. Senior management must be involved in this because they have an obligation to the organization to protect the assests . The requirement here is…
Question
Which must bear the primary responsibility for determining the level of protection needed for information systems resources?
Options
- AIS security specialists
- BSenior Management
- CSenior security analysts
- Dsystems Auditors
How the community answered
(35 responses)- A3% (1)
- B89% (31)
- C3% (1)
- D6% (2)
Explanation
If there is no support by senior management to implement, execute, and enforce security policies and procedure, then they won't work. Senior management must be involved in this because they have an obligation to the organization to protect the assests . The requirement here is for management to show "due diligence" in establishing an effective compliance, or security program. It is senior management that could face legal repercussions if they do not have sufficient controls in place. The following answers are incorrect: IS security specialists. Is incorrect because it is not the best answer. Senior management bears the primary responsibility for determining the level of protection needed. Senior security analysts. Is incorrect because it is not the best answer. Senior management bears the primary responsibility for determining the level of protection needed. systems auditors. Is incorrect because it is not the best answer, system auditors are responsible that the controls in place are effective. Senior management bears the primary responsibility for determining the level of protection needed.
Topics
Community Discussion
No community discussion yet for this question.