SSCP · Question #276
Who is responsible for initiating corrective measures and capabilities used when there are security violations?
The correct answer is C. Management. Management holds ultimate organizational authority and accountability, making them responsible for initiating corrective actions in response to security violations. While security administrators implement controls and auditors detect violations, only management has the…
Question
Who is responsible for initiating corrective measures and capabilities used when there are security violations?
Options
- AInformation systems auditor
- BSecurity administrator
- CManagement
- DData owners
How the community answered
(32 responses)- A6% (2)
- B3% (1)
- C91% (29)
Explanation
Management holds ultimate organizational authority and accountability, making them responsible for initiating corrective actions in response to security violations. While security administrators implement controls and auditors detect violations, only management has the authority and responsibility to authorize and drive corrective measures, allocate resources, and enforce policy changes across the organization. Data owners manage data classification but do not direct organizational response.
Topics
Community Discussion
No community discussion yet for this question.