Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard
A company recently migrated its entire IT infrastructure to a cloud provider. The security team is now reviewing the shared responsibility model. They need to define clearly who is accountable for securing the operating system, network configuration, and data encryption. This exercise is a key component of which security concept?
- ASecurity Operations
- BSecurity Metrics
- CSecurity Awareness Training
- DSecurity Governance
Show answer & explanationAnswer & explanation
Correct answer: D. Security Governance
Security governance involves defining roles, responsibilities, and accountability for security within an organization, especially critical when leveraging cloud services under a shared responsibility model. This exercise directly addresses who is accountable for different security aspects.
Why the other options are wrong
- A. Security operations are the day-to-day execution, not the strategic definition of responsibility.
- B. Security metrics measure performance, not define responsibility for controls.
- C. Security awareness training educates users, but doesn't define organizational accountability structures.
Security Governance
The framework of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction for security activities.
- Establishes roles, responsibilities, and accountability.
- Ensures security aligns with business objectives.
- Includes policies, standards, and oversight.
Memory trick: Governance is the 'GO' for 'Organizational' security 'VE'hicle's 'RN'ules and 'ANCE'stry.