Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 431 discussion

Actual exam question from Isaca's CISM
Question #: 431
Topic #: 1
[All CISM Questions]

Who is accountable for ensuring proper controls are in place to address the confidentiality and availability of an information system?

  • A. Information order
  • B. Business manager
  • C. Senior management
  • D. Information security manager
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
EZPASS
Highly Voted 2 years ago
Selected Answer: D
Yes, the answer should be D.
upvoted 7 times
...
Wladysk
Highly Voted 1 year, 9 months ago
Selected Answer: A
A is correct, but answer is misspelled "Information Owner". Information owner owns the risk of implementing proper controls.
upvoted 6 times
...
yottabyte
Most Recent 8 months ago
Selected Answer: C
Senior management is account table for ensuring. IS Manager is accountable for enforcing. the question is asking about ensuring and not enforcing.
upvoted 2 times
...
yottabyte
8 months ago
Selected Answer: C
Senior management should be accountable.
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: C
C. Senior management Senior management is ultimately accountable for ensuring proper controls are in place to address the confidentiality and availability of an information system. While the Information Security Manager plays a crucial role in implementing and managing these controls, the responsibility for overall governance and accountability rests with senior management within an organization. Senior management sets the strategic direction and policies for information security, allocates resources, and is responsible for making sure that the necessary measures are in place to protect the confidentiality and availability of information systems.
upvoted 2 times
e891cd1
4 months, 2 weeks ago
Ultimately accountable is much different from accountable...ultimately accountable is the highest level of accountability. Information owner and business owners are delegated accountability. I would agree with A. Information owner.
upvoted 1 times
Raven89
2 weeks, 6 days ago
it is ACCOUNTABLE, the other option is RESPONSABLE
upvoted 1 times
...
...
...
Manix
9 months, 3 weeks ago
Selected Answer: C
CRM 3.1: sen. management wantsto understand the specific risk ... and why the controls it mandates are a sound investment...
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
C. Senior management Senior management is ultimately accountable for ensuring proper controls are in place to address the confidentiality and availability of an information system. While the Information Security Manager plays a crucial role in implementing and managing these controls, the responsibility for overall governance and accountability rests with senior management within an organization. Senior management sets the strategic direction and policies for information security, allocates resources, and is responsible for making sure that the necessary measures are in place to protect the confidentiality and availability of information systems.
upvoted 3 times
...
Agamennore
1 year, 2 months ago
Selected Answer: D
it's D, it's the accountable and not the ultimate accountable in case of breach
upvoted 1 times
...
Akam
1 year, 3 months ago
Selected Answer: C
The answer is C. If your system compromised due to lack of security controls and launched a counter attack against another company's system, who will be ultimately accountability over this? It has to be Senior Management.
upvoted 5 times
...
Goseu
1 year, 4 months ago
C.Senior Management , in most cases SM is accountable .CISO is the responsible person for CIA triad.
upvoted 3 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
C. Senior Management is accountable. Information Security Manager is responsible
upvoted 4 times
...
richck102
1 year, 4 months ago
D. Information security manager
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: C
C. Senior management I based the answer on the keyword "accountable." Senior management holds the ultimate accountability for ensuring proper controls are in place to address the confidentiality and availability of an information system. They are responsible for setting the strategic direction of the organization, defining policies and objectives, allocating resources, and making decisions regarding risk management and control implementation. It is their role to provide oversight and governance to ensure that the necessary controls are established, maintained, and continuously improved to protect the organization's information assets. The information security manager, business managers, and other stakeholders play important roles in implementing and supporting these controls, but ultimate accountability lies with senior management.
upvoted 4 times
...
Dravidian
1 year, 6 months ago
Selected Answer: A
I did get thrown off by "information order" but like one the below comments says, if it's a typo and it means Information Owner then this definitely is the right answer. The respective owners are always accountable. ISM is a information custodian not the information owner.
upvoted 3 times
...
Ziggybooboo
2 years ago
Agreed
upvoted 3 times
...
k4d4v4r
2 years, 1 month ago
Selected Answer: D
It should be D
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...