ExamGecko
Question list
Search
Search

Question 391 - CISM discussion

Report
Export

Which of the following BEST enables the assignment of risk and control ownership?

A.
Aligning to an industry-recognized control framework
Answers
A.
Aligning to an industry-recognized control framework
B.
Adopting a risk management framework
Answers
B.
Adopting a risk management framework
C.
Obtaining senior management buy-in
Answers
C.
Obtaining senior management buy-in
D.
Developing an information security strategy
Answers
D.
Developing an information security strategy
Suggested answer: C

Explanation:

Obtaining senior management buy-in is the best way to enable the assignment of risk and control ownership because it helps to establish the authority and accountability of the risk and control owners, as well as to provide them with the necessary resources and support to perform their roles. Risk and control ownership refers to the assignment of specific responsibilities and accountabilities for managing risks and controls to individuals or groups within the organization. Obtaining senior management buy-in helps to ensure that risk and control ownership is aligned with the organizational objectives, structure, and culture, as well as to communicate the expectations and benefits of risk and control ownership to all stakeholders. Therefore, obtaining senior management buy-in is the correct answer.

https://www.protechtgroup.com/en-au/blog/risk-control-management

https://www.mckinsey.com/~/media/mckinsey/dotcom/client_service/risk/working%20papers/23_getting_risk_ownership_right.ashx

https://www.linkedin.com/pulse/risk-controls-who-owns-them-david-tattam

asked 01/10/2024
Danilo Ferrareis
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first