ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 577 - CGEIT discussion

Report
Export

Which of the following is MOST likely to have a negative impact on accountability for information risk ownership?

A.

The risk owner is a department manager, and the control owner is a member of the risk owner's staff.

Answers
A.

The risk owner is a department manager, and the control owner is a member of the risk owner's staff.

B.

Information risk is assigned to a department, and an individual owner has not been assigned.

Answers
B.

Information risk is assigned to a department, and an individual owner has not been assigned.

C.

The risk owner and the control owner of the information do not work in the same department.

Answers
C.

The risk owner and the control owner of the information do not work in the same department.

D.

The same person is listed as both the control owner and the risk owner for the information.

Answers
D.

The same person is listed as both the control owner and the risk owner for the information.

Suggested answer: B

Explanation:

Assigning information risk to a department without designating an individual owner is most likely to have a negative impact on accountability for information risk ownership. This lack of individual accountability can lead to ambiguities in responsibility, making it difficult to ensure that appropriate risk management actions are taken and followed up on. When an individual owner is clearly identified, it establishes direct responsibility and accountability, improving the effectiveness of risk management practices. While the scenarios described in the other options present challenges, the absence of a specific individual owner represents a fundamental weakness in establishing clear accountability for managing information risk.

asked 18/11/2024
Melvin Masina
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first