Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 SSCP Exam - Topic 3 Question 119 Discussion

Who is ultimately responsible for the security of computer based information systems within an organization?
C) The management team.
A) The tech support team
B) The Operation Team.
D) The training team.

ISC2 SSCP Exam - Topic 3 Question 119 Discussion

Actual exam question for ISC2's SSCP exam
Question #: 119
Topic #: 3
[All SSCP Questions]

Who is ultimately responsible for the security of computer based information systems within an organization?

Show Suggested Answer Hide Answer
Suggested Answer: C

If there is no support by management to implement, execute, and enforce security policies and procedure, then they won't work. Senior management must be involved in this because they have an obligation to the organization to protect the assests . The requirement here is for management to show ''due diligence'' in establishing an effective compliance, or security program.

The following answers are incorrect:

The tech support team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems.

The Operation Team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems.

The Training Team. Is incorrect because the ultimate responsibility is with management for the security of computer-based information systems.

Reference(s) used for this question:

OIG CBK

Information Security Management and Risk Management (page 20 - 22)


Contribute your Thoughts:

0/2000 characters
Lemuel
3 days ago
Management team is key. They allocate resources for security.
upvoted 0 times
...
Amie
9 days ago
I agree, but the tech support team handles the actual security measures.
upvoted 0 times
...
Tamala
14 days ago
I think it's definitely the management team. They set the policies.
upvoted 0 times
...
Lorean
19 days ago
I think it's a shared responsibility, can't just pin it on one team!
upvoted 0 times
...
Magdalene
24 days ago
Surprised to see training team listed at all, they don't really control security.
upvoted 0 times
...
Crista
29 days ago
Totally agree, management needs to take responsibility for security.
upvoted 0 times
...
Judy
1 month ago
I don't know, the tech support team handles a lot of the security stuff.
upvoted 0 times
...
Antonio
1 month ago
It's definitely the management team. They set the policies!
upvoted 0 times
...
Verona
1 month ago
I recall that the management team sets the tone for security, but I wonder if the operations team has a direct responsibility too.
upvoted 0 times
...
Barb
2 months ago
I’m a bit confused here. I thought the training team was responsible for educating staff on security, but does that make them responsible overall?
upvoted 0 times
...
Stefania
2 months ago
I feel like this question is similar to one we practiced about roles in cybersecurity. I want to say it's management, but the tech support team also plays a big role.
upvoted 0 times
...
Irma
2 months ago
I think I remember that management is usually held accountable for security policies, but I'm not entirely sure if they handle everything directly.
upvoted 0 times
...

Save Cancel