Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

As part of cyber security governance, a listed company's board wants a single accountable executive to design the information security programme, report risks to the board and oversee incident response. Which role best fits this responsibility?

The Chief Information Security Officer is the best fit, because the role owns the information security strategy, reports cyber risks to the board and senior management, and oversees incident response, unlike an independent auditor or a technical administrator with only operational duties.

  1. AChief Information Security OfficerCorrect
  2. BCompany Secretary acting as the Registrar of Members
  3. CStatutory auditor
  4. DNetwork administrator handling daily routers

Explanation

A Chief Information Security Officer owns the security strategy, risk reporting to senior management and the board, and incident response oversight. A statutory auditor is independent and cannot run the programme. A network administrator handles operations only, not enterprise-level governance.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions