CISSP · Free practice question 1 of 12
Senior management ultimate security accountability
A breach at Kilbride Outfitters exposed thousands of customer records. The board wants to confirm where ultimate accountability for protecting the organization's information assets lies. Who carries this accountability?
- A.Each employee whose account was used in the breach
- B.The help desk staff who reset user passwords
- C.Senior management, led by the chief executive and the board
- D.The network team that operates the firewalls
Show answer and explanation
Correct answer: C. Senior management, led by the chief executive and the board
Why: Senior management holds ultimate responsibility for protecting the organization's assets; it may delegate security tasks to the CISO and technical teams, but it cannot delegate the accountability. Network teams, help desk staff and individual users perform specific duties within the security program, yet none of them own the overall responsibility to the board, regulators and shareholders.
More free CISSP questions
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Known-plaintext cryptanalytic attack
- Air-gapped network physical segmentation
- Role-based access control by job function
- Misuse case testing of abuse scenarios
- Breach and attack simulation platforms
- Proactive hypothesis-driven threat hunting
- Lessons learned after incident closure
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time