New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSEP Exam - Topic 3 Question 29 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 29
Topic #: 3
[All ISSEP Questions]

Which of the following individuals is responsible for monitoring the information system environment

for factors that can negatively impact the security of the system and its accreditation?

Show Suggested Answer Hide Answer
Suggested Answer: D

The Information System Owner is responsible for monitoring the information system environment

for factors that can negatively impact the

security of the system and its accreditation.

Answer option C is incorrect. A Chief Risk Officer (CRO) is also known as Chief Risk Management

Officer (CRMO). The Chief Risk Officer or Chief

Risk Management Officer of a corporation is the executive accountable for enabling the efficient and

effective governance of significant risks,

and related opportunities, to a business and its various segments. Risks are commonly categorized as

strategic, reputational, operational,

financial, or compliance-related. CRO's are accountable to the Executive Committee and The Board

for enabling the business to balance risk

and reward. In more complex organizations, they are generally responsible for coordinating the

organization's Enterprise Risk Management

(ERM) approach.

Answer option A is incorrect. The Chief Information Officer (CIO), or Information Technology (IT)

director, is a job title commonly given to the

most senior executive in an enterprise responsible for the information technology and computer

systems that support enterprise goals. The

CIO plays the role of a leader and reports to the chief executive officer, chief operations officer, or

chief financial officer. In military

organizations, they report to the commanding officer.

Answer option B is incorrect. A Chief Information Security Officer (CISO) is the senior-level executive

within an organization responsible for

establishing and maintaining the enterprise vision, strategy, and program to ensure information

assets are adequately protected. The CISO

directs staff in identifying, developing, implementing, and maintaining processes across the

organization to reduce Information Technology (IT)

risks, respond to incidents, establish appropriate standards and controls, and direct the

establishment and implementation of policies and

procedures. The CISO is also usually responsible for information-related compliance.

The responsibilities of a CISO are as follows:

Information security and information assurance

Information regulatory compliance (e.g., US PCI DSS, FISMA, GLBA, HIPAA; UK Data Protection Act

1998; Canada PIPEDA)

Information risk management

Information technology controls for financial and other systems

Information privacy

Computer Emergency Response Team (CERT)/ Computer Security Incident Response Team (CSIRT)

Identity and access management

Disaster recovery and business continuity management


Contribute your Thoughts:

0/2000 characters
Nathan
4 months ago
Wait, are we sure about that? Sounds too simple!
upvoted 0 times
...
Gail
4 months ago
I agree, CISO is the right choice here.
upvoted 0 times
...
Lucina
4 months ago
Nope, it's the Information System Owner for sure.
upvoted 0 times
...
Johna
4 months ago
I thought it was the Chief Risk Officer?
upvoted 0 times
...
Dion
5 months ago
Definitely the Chief Information Security Officer!
upvoted 0 times
...
Jolanda
5 months ago
I’m confused about the roles. I thought the CIO was more about overall IT strategy, not just security monitoring.
upvoted 0 times
...
Precious
5 months ago
I feel like the Information System Owner might have some responsibility too, but I’m leaning towards the CISO.
upvoted 0 times
...
Gregoria
5 months ago
I remember a practice question where the Chief Risk Officer was mentioned in a similar context. Could it be them?
upvoted 0 times
...
Emelda
5 months ago
I think the Chief Information Security Officer is the right choice since they focus on security risks, but I'm not entirely sure.
upvoted 0 times
...
Mattie
5 months ago
This seems like a pretty straightforward question about the Huawei OceanStor 9000 system. I think I can handle this one.
upvoted 0 times
...
Cherrie
5 months ago
Okay, I see. So we only count the story points for the stories that were fully completed and accepted by the Product Owner. That makes sense. I'm feeling more confident about this now.
upvoted 0 times
...

Save Cancel