Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 16 discussion

Actual exam question from Isaca's CISM
Question #: 16
Topic #: 1
[All CISM Questions]

The PRIMARY reason for defining the information security roles and responsibilities of staff throughout an organization is to:

  • A. comply with security policy.
  • B. increase corporate accountability.
  • C. enforce individual accountability.
  • D. reinforce the need for training.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Jess20
1 month ago
Selected Answer: C
C. Enforce *individual* accountability
upvoted 1 times
...
BamBamBigalo
1 month, 3 weeks ago
C. Enforce individual accountability. Enforcing individual accountability is indeed a primary reason for defining roles and responsibilities. When staff members have clearly defined roles and responsibilities, they understand what is expected of them and can be held accountable for their actions. This clarity helps to ensure that each person knows their specific duties related to information security, which is essential for maintaining a secure environment.
upvoted 1 times
...
Viperhunter
1 month, 3 weeks ago
Selected Answer: C
Defining information security roles and responsibilities helps enforce individual accountability by clarifying who is responsible for specific security tasks, actions, or decisions within the organization. It establishes a framework for accountability and helps ensure that individuals understand their roles in protecting the organization's information assets. This clarity is crucial for creating a culture of security and promoting responsible behavior among employees. While compliance with security policy (option A), increasing corporate accountability (option B), and reinforcing the need for training (option D) are important considerations, the primary goal is often to ensure that individuals understand and fulfill their specific responsibilities in maintaining information security.
upvoted 2 times
...
greeklover84
2 months ago
Selected Answer: C
agree C makes sense.
upvoted 1 times
...
shervin2s
8 months, 2 weeks ago
Selected Answer: C
C is correct!
upvoted 1 times
...
XJ
1 year ago
C -"Individual accountability ensures that individuals are held responsible for their actions related to information security, which promotes adherence to policy, procedures and guidelines. Defining roles and responsibilities helps make clear what is expected of each staff member, which in turn makes it possible to hold individuals accountable for fulfilling those expectations. This encourages behavior that supports the organization’s information security objectives.
upvoted 1 times
...
chanke
1 year, 4 months ago
Selected Answer: C
Enforce it at the lowest level. C. individual accountability
upvoted 3 times
...
Jae_kes
1 year, 5 months ago
C. enforce individual accountability.
upvoted 3 times
...
richck102
1 year, 6 months ago
C. enforce individual accountability.
upvoted 3 times
...
mad68
1 year, 6 months ago
Selected Answer: B
Seems like they are talking about the entire staff and what enforcement mechanism is discussed in the question. I think B. increase corporate accountability. Also, ChatGPT states: The primary reason for defining the information security roles and responsibilities of staff throughout an organization is to increase corporate accountability. This means that everyone within the organization, from top management to entry-level employees, understands their roles and responsibilities for maintaining the security of the organization's information assets.
upvoted 2 times
Monkey2173
1 year, 6 months ago
The staff is built from individuals. The roles and responsibilities must be defined individually to create clarity and by that - enforce individual accountability
upvoted 4 times
...
...
mad68
1 year, 6 months ago
Seems like they are talking about the entire staff and what enforcement mechanism is discussed in the question. I think B. increase corporate accountability. Also, ChatGPT states: The primary reason for defining the information security roles and responsibilities of staff throughout an organization is to increase corporate accountability. This means that everyone within the organization, from top management to entry-level employees, understands their roles and responsibilities for maintaining the security of the organization's information assets.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...