exam questions

Exam SSCP All Questions

View all questions & answers for the SSCP exam

Exam SSCP topic 3 question 31 discussion

Actual exam question from ISC's SSCP
Question #: 31
Topic #: 3
[All SSCP Questions]

Who is responsible for providing reports to the senior management on the effectiveness of the security controls?

  • A. Information systems security professionals
  • B. Data owners
  • C. Data custodians
  • D. Information systems auditors
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
IT auditors determine whether systems are in compliance with the security policies, procedures, standards, baselines, designs, architectures, management direction and other requirements" and "provide top company management with an independent view of the controls that have been designed and their effectiveness."
"Information systems security professionals" is incorrect. Security professionals develop the security policies and supporting baselines, etc.
"Data owners" is incorrect. Data owners have overall responsibility for information assets and assign the appropriate classification for the asset as well as ensure that the asset is protected with the proper controls.
"Data custodians" is incorrect. Data custodians care for an information asset on behalf of the data owner.
References:
CBK, pp. 38 - 42.
AIO3. pp. 99 - 104

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Currently there are no comments in this discussion, be the first to comment!
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...