ExamGecko
Question list
Search
Search

Question 635 - CISM discussion

Report
Export

An organization has implemented a new customer relationship management (CRM) system. Who should be responsible for enforcing authorized and controlled access to the CRM data?

A.
The information security manager
Answers
A.
The information security manager
B.
The data custodian
Answers
B.
The data custodian
C.
Internal IT audit
Answers
C.
Internal IT audit
D.
The data owner
Answers
D.
The data owner
Suggested answer: B

Explanation:

The data custodian is the person or role who is responsible for enforcing authorized and controlled access to the CRM data, according to the security policies and standards defined by the data owner. The data custodian implements and maintains the technical and operational controls, such as authentication, authorization, encryption, backup, and recovery, to protect the data from unauthorized access, modification, disclosure, or destruction. The data custodian also monitors and reports on the data access activities and incidents.

Reference=Setting Up Access Controls and Permissions in Your CRM,Accountability for Information Security Roles and Responsibilities, Part 1,How to Meet the Shared Responsibility Model with CIS

asked 01/10/2024
Adilet Abdikhamit
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first