Who is assigned the responsibility for administering user accounts, including additions, deletions, and modifications?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Who is assigned the responsibility for administering user accounts, including additions, deletions, and modifications?

Explanation:
Managing user accounts is a security governance task. The information security management group is responsible for defining and enforcing the policy for provisioning, modifying, and deprovisioning accounts, ensuring that each user has appropriate access, that changes are authorized, and that access is revoked promptly when someone leaves or changes roles. This centralized responsibility guarantees consistent application of least-privilege principles, proper auditing, and accountability across all systems. The other groups mentioned—the finance team, external vendors, and the marketing team—do not typically own or enforce access-control policies, so they aren’t the appropriate assignee for administering user accounts.

Managing user accounts is a security governance task. The information security management group is responsible for defining and enforcing the policy for provisioning, modifying, and deprovisioning accounts, ensuring that each user has appropriate access, that changes are authorized, and that access is revoked promptly when someone leaves or changes roles. This centralized responsibility guarantees consistent application of least-privilege principles, proper auditing, and accountability across all systems. The other groups mentioned—the finance team, external vendors, and the marketing team—do not typically own or enforce access-control policies, so they aren’t the appropriate assignee for administering user accounts.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy