Question 1
A multinational financial services firm is restructuring its governance framework to align with the Three Lines of Defense model. As the Information Systems Security Management Professional (ISSMP), you are defining the specific responsibilities of the second line of defense regarding information security. Which of the following responsibilities is MOST appropriate for this line?
Answer and explanation
Correct answer: C
In the Three Lines of Defense model, the second line is responsible for the risk management and compliance functions. This involves setting policies, monitoring risk levels, and overseeing the first line (management/operations) to ensure compliance. The first line implements controls, and the third line (internal audit) provides independent assurance.