medium
Single Answer
0Which one of the following individuals would be the most effective organizational owner for an information security program?
Answer Options
A
CISSP-certified analyst
B
Chief information officer (CIO)
C
Manager of network security
D
President and CEO
Correct Answer: B
Explanation
The owner of information security programs may be different from the individuals responsible for implementing the controls. This person should be as senior an individual as possible who is able to focus on the management of the security program. The president and CEO would not be an appropriate choice because an executive at this level is unlikely to have the time necessary to focus on security. Of the remaining choices, the CIO is the most senior position who would be the strongest advocate at the executive level.