QuestionQ1583

Governance

A system interruption was traced to an IT employee’s personal USB device being connected to the corporate network after the employee bypassed internal control procedures. Who should be accountable?

  • A Chief risk officer (CRO)
  • B Business continuity manager (BCM)
  • C Human resources manager (HRM)
  • D Chief information officer (CIO)
Explanation

The chief information officer (CIO) is accountable for governance and control of the organization’s IT environment, including implementing and enforcing controls that prevent unauthorized personal devices from connecting to the corporate network. Human resources may manage disciplinary action, but it does not own accountability for IT control effectiveness.

Community Discussion

No comments yet. Be the first to start the discussion!