nerdexam
(ISC)2

SSCP · Question #991

Who should DECIDE how a company should approach security and what security measures should be implemented?

The correct answer is A. Senior management. They are responsible for security of the organization and the protection of its assets. The following answers are incorrect because : Data owner is incorrect as data owners should not decide as to what security measures should Auditor is also incorrect as auditor cannot decide…

Submitted by anna_se· Apr 18, 2026Security Concepts and Practices

Question

Who should DECIDE how a company should approach security and what security measures should be implemented?

Options

  • ASenior management
  • BData owner
  • CAuditor
  • DThe information security specialist

How the community answered

(34 responses)
  • A
    94% (32)
  • C
    3% (1)
  • D
    3% (1)

Explanation

They are responsible for security of the organization and the protection of its assets. The following answers are incorrect because : Data owner is incorrect as data owners should not decide as to what security measures should Auditor is also incorrect as auditor cannot decide as to what security measures should be applied. The information security specialist is also incorrect as they may have the technical knowledge of how security measures should be implemented and configured , but they should not be in a position of deciding what measures should be applied.

Topics

#Security Governance#Roles and Responsibilities#Security Management#Organizational Security

Community Discussion

No community discussion yet for this question.

Full SSCP Practice