PrepAway - Latest Free Exam Questions & Answers

Which of the following would be best suited to oversee …

Which of the following would be best suited to oversee the development of an information security policy?

PrepAway - Latest Free Exam Questions & Answers

A.
System Administrators

B.
End User

C.
Security Officers

D.
Security administrators

Explanation:
The chief security officer (CSO) is responsible for understanding the risks that the company faces and for
mitigating these risks to an acceptable level. This role is responsible for understanding the organization’s
business drivers and for creating and maintaining a security program that facilitates these drivers, along with
providing security, compliance with a long list of regulations and laws, and any customer expectations or
contractual obligations.
Incorrect Answers:
A: System Administrators work in the IT department and manage the IT infrastructure from a technical
perspective. They do not specialize in security and are therefore not best suited to oversee the development of
an information security policy.
B: End users are the least qualified to oversee the development of an information security policy.
D: The security administrator is responsible for implementing and maintaining specific security network devices
and software in the enterprise. Security administrators are not best suited to oversee the development of an
information security policy.

Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 119-122


Leave a Reply