exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 468 discussion

Actual exam question from Isaca's CRISC
Question #: 468
Topic #: 1
[All CRISC Questions]

An organization has outsourced its IT security management function to an external service provider. The BEST party to own the IT security controls under this arrangement is the:

  • A. organization's risk function
  • B. service provider's audit function
  • C. organization's IT management
  • D. service provider's IT security function
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ankitislucky
6 days, 3 hours ago
Selected Answer: D
I agree it should be D.
upvoted 1 times
...
eblue
4 months ago
D. According to ISACA, when an organization outsources its IT security management function to an external service provider, the service provider’s IT security function is the best party to own the IT security controls under this arrangement. The service provider’s IT security function should be responsible for ensuring that the organization’s IT security controls are implemented and maintained in accordance with the agreed-upon service level agreements (SLAs) .
upvoted 2 times
...
eblue
4 months ago
According to ISACA, when an organization outsources its IT security management function to an external service provider, the service provider’s IT security function is the best party to own the IT security controls under this arrangement. The service provider’s IT security function should be responsible for ensuring that the organization’s IT security controls are implemented and maintained in accordance with the agreed-upon service level agreements (SLAs) .
upvoted 1 times
...
01010100
5 months, 1 week ago
Selected Answer: A
A. organization's risk function Even when an organization outsources its IT security management function, the ultimate responsibility for the organization's security posture remains with the organization itself. The service provider can be in charge of day-to-day management, but the organization's risk function should own the IT security controls. This is because the risk function understands the organization's risk tolerance and business objectives, and therefore is best positioned to ensure the controls meet these requirements. Even if the service provider implements, manages, or monitors controls, it's the organization's responsibility to ensure they are adequate and functioning correctly. Outsourcing security functions doesn't relieve the organization of the responsibility for its own security.
upvoted 1 times
...
CbtL
9 months, 2 weeks ago
Selected Answer: A
The IT Security function should be separate from the main IT function. The third party should not own the control as in this case they are the control, as it were. Leaves A.
upvoted 1 times
...
john_boogieman
10 months, 2 weeks ago
Selected Answer: A
Sorry, I rectify by 'A'. The risk function is responsible for identifying and managing risks that could impact the organization's business objectives. It has a broader view of the organization's risk landscape and is best positioned to oversee the IT security controls that are in place to mitigate those risks. Additionally, the risk function typically has the authority to make decisions that affect the organization's risk posture and can ensure that the IT security controls implemented by the external service provider are aligned with the organization's overall risk management strategy.
upvoted 2 times
...
helg420
10 months, 2 weeks ago
Selected Answer: C
C. The Organization IT Management will own the security controls. The outsourcing was done for the security management.
upvoted 2 times
...
Jco
1 year, 1 month ago
Why not C. organization's IT management
upvoted 1 times
...
tsangckl
1 year, 9 months ago
I g will go for C
upvoted 3 times
...
Khy
2 years, 8 months ago
why not D?
upvoted 1 times
BeeSz
2 years, 6 months ago
Responsibility still lies with the Org. Think of it as who would be liable if anything occurred, that would still fall under the Org's jurisdiction.
upvoted 1 times
fora
1 year, 10 months ago
Have you ever seen Risk unit being the Owner of the implemented controls? They are not for that, ownership would be with someone who actually is taking care of it. I'd say, it would be either IT or IT Security. But as we outsourced it, why would the ownership be still wit the organization? Responsibility is another thing, I show my due care driven by the responsibility making e.g. regular vendor audits, but all the operational burden that is related to the controls' ownership should be within the vendor, isn't it?
upvoted 2 times
john_boogieman
11 months ago
What is outsourced is 'security management', nothing says that IT management will disappear. C is ok.
upvoted 1 times
...
Ceecil1959
1 year, 8 months ago
Ownership will also be with the organization and never with the outsourced vendor or contractor. And with ownership comes accountability. So no matter who is responsible for operational duties and processes, the actual ownership lies with the organisation.
upvoted 2 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago