ExamGecko
Question list
Search
Search

Question 328 - CISM discussion

Report
Export

Of the following, who is MOST appropriate to own the risk associated with the failure of a privileged access control?

A.
Data owner
Answers
A.
Data owner
B.
Business owner
Answers
B.
Business owner
C.
Information security manager
Answers
C.
Information security manager
D.
Compliance manager
Answers
D.
Compliance manager
Suggested answer: B

Explanation:

The business owner is the most appropriate person to own the risk associated with the failure of a privileged access control because they are ultimately responsible for the protection and use of the information in their business unit1.The data owner is responsible for determining the access rights for specific data sets, but not for the access control mechanisms2.The information security manager is responsible for implementing and enforcing the security policies and standards, but not for owning the risk3.The compliance manager is responsible for ensuring that the organization meets the regulatory requirements, but not for owning the risk3.

Reference:1https://www.cyberark.com/resources/blog/how-do-you-prioritize-risk-for-privileged-access-management3https://www.isaca.org/resources/isaca-journal/issues/2017/volume-1/capability-framework-for-privileged-access-management2https://security.stackexchange.com/questions/218049/what-is-the-difference-between-data-owner-data-custodian-and-system-owner

asked 01/10/2024
Lucia Montero Tejeda
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first