QuestionQ1541

Governance

An organization implemented a preventive control that locks user accounts after three failed login attempts. This practice has been shown to be ineffective, and a modification to the control-threshold value has been recommended. Who should authorize this threshold change?

  • A Control owner
  • B IT security manager
  • C Risk owner
  • D IT system owner
Explanation

The control owner is accountable for ensuring that a control is appropriately designed and operates effectively. A change to the account-lockout threshold changes the preventive control’s configuration and effectiveness, so it requires the control owner’s authorization.

Community Discussion

No comments yet. Be the first to start the discussion!