Which of the following is the BEST method to ensure that data owners take responsibility for implementing information security processes?
A. Include security tasks into employee job descriptions.
B. Include membership on project teams.
C. Provide job rotation into the security organization.
D. Increase security awareness training.
Correct Answer: ????????????????
____________________
■ Answer D (Increase security awareness training) is officially believed to be the correct one.
■ But I believe it is weak because there is no accountability
■ Please enter an explanation of why that answer is correct and why the others are not.
Many Thanks!
This question is a controversial one and can be interprerted in different ways by others. I am placing my opinions here which I see best fit after working in the domain. I will be explaining the options one at a time.
a. Checking employee job desciptions and determining whether or not data owners are concerned about safety of data is the most miserable wayto go about it. In most cases the job descriptions are made bulky and even flattered while the requirement is quite low.
b. Including membership on projects can be a good step to give a transparency but it can't be considered the best way either.
c. Providing job rotation to security organization is actually a very good example displaying that the data owners are actually providing opportunities in the field of their need. This can be considered. Let's look at the remaining option and then decide.
d. Increasing security awareness training among the employees is a very prefereable way to encourage more people to switch their domains and it definitely displays the concern of the data owners.
Now if looked at once then it seems that option C is the best but if you consider, a major part of C may depend upon option D. Obviously if a company want employees to otate their domain they would prefer the ones who trained under them rather than holding separate metrics of choice.
So the answer id option D.
Get Answers For Free
Most questions answered within 1 hours.