Certified Information Security Manager (CISM) — Question 489
Embedding security responsibilities into job descriptions is important PRIMARILY because it:
Answer options
- A. simplifies development of the security awareness program
- B. aligns security to the human resources (HR) function
- C. strengthens employee accountability
- D. supports access management.
Correct answer: C
Explanation
The correct answer is C because embedding security responsibilities into job descriptions ensures that employees understand their role in maintaining security, which fosters accountability. Options A and B, while relevant, do not directly address the core purpose of accountability, and option D focuses on access management, which is a different aspect of security.