An organization wants a single practice to own keeping the data its business runs on safe from disclosure, tampering and loss. Which practice is that?
ITIL 4 Foundation, objective 6. Purpose and key terms of 15 ITIL practices medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct Service configuration management
Service configuration management ensures accurate and reliable information about services and their configuration items is available when needed. Its concern is accuracy and availability of configuration data, not protection of business information generally.
Correct Information security management
Correct. This is the practice whose whole reason for existing is safeguarding business data, and it is usually described through five properties: confidentiality, integrity, availability, authentication and non-repudiation.
Not correct Continual improvement
Continual improvement keeps what the organization does in step with what the business now needs, by improving it repeatedly rather than once. Security controls may well be improved through it, but protecting anything is not what it is for.
Not correct IT asset management
IT asset management plans and manages the full lifecycle of IT assets to maximize value and control cost and risk. It protects the financial and contractual position, not the information itself.
Why
Information security management is stated in terms of the information, not the technology: the objective is protection of what the business needs to operate. Availability appears here as a security property, which is why it must not be read as duplicating the availability targets that service level management agrees with the customer.
Where this comes from
- Cited
- ITIL 4 syllabus clause 6
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 6 and space the ones you get wrong.
More questions on this objective
- A practice is responsible for making new and changed services and features available for use. Which practice is described? machine-checked
- Which statement best describes the purpose of the deployment management practice? machine-checked
- An organization wants to increase how many of its product and service changes succeed, by making sure risk is properly assessed before work is authorized and by keeping an accurate schedule of authorized work. Which practice has this as its purpose? machine-checked
- An organization wants a practice that ensures its suppliers and their performance are managed appropriately, so that a seamless quality of products and services is provided. Which practice is this? machine-checked
- Which practice systematically observes services and service components, records and reports selected changes of state, and establishes the appropriate response to them? machine-checked
- Which pair correctly matches the ITIL 4 definitions of 'incident' and 'problem'? machine-checked