SSCP · Question #991
Who should DECIDE how a company should approach security and what security measures should be implemented?
The correct answer is A. Senior management. They are responsible for security of the organization and the protection of its assets. The following answers are incorrect because : Data owner is incorrect as data owners should not decide as to what security measures should Auditor is also incorrect as auditor cannot decide…
Question
Who should DECIDE how a company should approach security and what security measures should be implemented?
Options
- ASenior management
- BData owner
- CAuditor
- DThe information security specialist
How the community answered
(34 responses)- A94% (32)
- C3% (1)
- D3% (1)
Explanation
They are responsible for security of the organization and the protection of its assets. The following answers are incorrect because : Data owner is incorrect as data owners should not decide as to what security measures should Auditor is also incorrect as auditor cannot decide as to what security measures should be applied. The information security specialist is also incorrect as they may have the technical knowledge of how security measures should be implemented and configured , but they should not be in a position of deciding what measures should be applied.
Topics
Community Discussion
No community discussion yet for this question.