An organization wants a single practice to own keeping the data its business runs on safe from disclosure, tampering and loss. Which practice is that?

ITIL 4 Foundation, objective 6. Purpose and key terms of 15 ITIL practices medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct Service configuration management

Service configuration management ensures accurate and reliable information about services and their configuration items is available when needed. Its concern is accuracy and availability of configuration data, not protection of business information generally.

Correct Information security management

Correct. This is the practice whose whole reason for existing is safeguarding business data, and it is usually described through five properties: confidentiality, integrity, availability, authentication and non-repudiation.

Not correct Continual improvement

Continual improvement keeps what the organization does in step with what the business now needs, by improving it repeatedly rather than once. Security controls may well be improved through it, but protecting anything is not what it is for.

Not correct IT asset management

IT asset management plans and manages the full lifecycle of IT assets to maximize value and control cost and risk. It protects the financial and contractual position, not the information itself.

Why

Information security management is stated in terms of the information, not the technology: the objective is protection of what the business needs to operate. Availability appears here as a security property, which is why it must not be read as duplicating the availability targets that service level management agrees with the customer.

Where this comes from

Cited
ITIL 4 syllabus clause 6

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 6 and space the ones you get wrong.

Practise ITIL 4 Foundation

More questions on this objective

All questions on Purpose and key terms of 15 ITIL practices

Practise ITIL 4 Foundation