QuestionQ759

Governance

Who is responsible for authorizing internal users’ access to an information system?

  • A Information security manager
  • B Information owner
  • C Information custodian
  • D Information security officer
Explanation

The information owner is accountable for authorizing access because the owner determines the appropriate use of the information and which users have a legitimate business need to access it. Custodians administer the access controls, while security management and security officers govern or oversee the security program.

Community Discussion

No comments yet. Be the first to start the discussion!