Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Exam CISM Topic 1 Question 79 Discussion

Actual exam question for Isaca's CISM exam
Question #: 79
Topic #: 1
[All CISM Questions]

Of the following, who is accountable for data loss in the event of an information security incident at a third-party provider?

Show Suggested Answer Hide Answer
Suggested Answer: A

Mitigate is the risk treatment option that has been applied by implementing a firewall in front of the legacy application because it helps to reduce the impact or probability of a risk. Mitigate is a process of taking actions to lessen the negative effects of a risk, such as implementing security controls, policies, or procedures. A firewall is a security device that monitors and filters the network traffic between the legacy application and the external network, blocking or allowing packets based on predefined rules. A firewall helps to mitigate the risk of unauthorized access, exploitation, or attack on the legacy application that cannot be patched. Therefore, mitigate is the correct answer.


https://simplicable.com/risk/risk-treatment

https://resources.infosecinstitute.com/topic/risk-treatment-options-planning-prevention/

https://www.enisa.europa.eu/topics/risk-management/current-risk/risk-management-inventory/rm-process/risk-treatment.

Contribute your Thoughts:

Micaela
1 months ago
I don't know, man. I'm just hoping the correct answer isn't 'all of the above'. That would be a real plot twist, am I right?
upvoted 0 times
...
Maybelle
1 months ago
Hmm, I'm gonna have to go with the business data owner on this one. After all, they're the ones who decided to outsource their data, so they should be prepared to deal with the consequences.
upvoted 0 times
...
Juliann
1 months ago
The information security manager is the one who's supposed to be overseeing all this, so they should be the ones held accountable. No one else is gonna take the fall for their mistakes.
upvoted 0 times
Wilbert
7 days ago
The business data owner might also share some responsibility in ensuring data protection.
upvoted 0 times
...
Demetra
15 days ago
I agree, they are responsible for overseeing data security.
upvoted 0 times
...
Aide
18 days ago
The information security manager should definitely be held accountable.
upvoted 0 times
...
...
Sherman
1 months ago
I'm going with the incident response team on this one. They're the ones who are supposed to handle security incidents, so they should be the ones responsible.
upvoted 0 times
...
Marshall
1 months ago
Nah, it's definitely the service provider's responsibility. They're the ones hosting the data, so they should be the ones held accountable.
upvoted 0 times
Alexia
17 days ago
C) The incident response team
upvoted 0 times
...
Wilda
30 days ago
B) The service provider that hosts the data
upvoted 0 times
...
Aleisha
1 months ago
A) The information security manager
upvoted 0 times
...
...
Tequila
2 months ago
I think the business data owner should be accountable for data loss at a third-party provider. They're the ones who entrusted the data to the provider in the first place.
upvoted 0 times
Diego
9 days ago
D) The business data owner
upvoted 0 times
...
Viki
11 days ago
C) The incident response team
upvoted 0 times
...
Carole
1 months ago
B) The service provider that hosts the data
upvoted 0 times
...
Ma
1 months ago
A) The information security manager
upvoted 0 times
...
...
Brittni
2 months ago
But what about the service provider that hosts the data? Shouldn't they also be accountable?
upvoted 0 times
...
Pearlie
2 months ago
I agree with Laticia. The business data owner should be responsible for protecting the data.
upvoted 0 times
...
Laticia
3 months ago
I think the business data owner is accountable for data loss.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77