ExamGecko
Question list
Search
Search

Question 261 - CISM discussion

Report
Export

Which of the following is the MOST important reason for obtaining input from risk owners when implementing controls?

A.
To reduce risk mitigation costs
Answers
A.
To reduce risk mitigation costs
B.
To resolve vulnerabilities in enterprise architecture (EA)
Answers
B.
To resolve vulnerabilities in enterprise architecture (EA)
C.
To manage the risk to an acceptable level
Answers
C.
To manage the risk to an acceptable level
D.
To eliminate threats impacting the business
Answers
D.
To eliminate threats impacting the business
Suggested answer: C

Explanation:

According to the Certified Information Security Manager (CISM) Study Manual, risk owners are responsible for managing a risk, including taking corrective action to reduce the risk to an acceptable level. When implementing controls, it is essential to obtain input from risk owners to ensure that the controls are effective in managing the risk to an acceptable level.

By obtaining input from risk owners, the organization can ensure that the controls are tailored to the specific risks and are effective in reducing the risk to an acceptable level. This can help to minimize the impact of the risk on the organization and reduce the potential for financial or reputational damage.

asked 01/10/2024
Albert Tedjadiputra
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first