ExamGecko
Question list
Search
Search

Question 416 - CISM discussion

Report
Export

When assigning a risk owner, the MOST important consideration is to ensure the owner has:

A.
adequate knowledge of risk treatment and related control activities.
Answers
A.
adequate knowledge of risk treatment and related control activities.
B.
decision-making authority and the ability to allocate resources for risk.
Answers
B.
decision-making authority and the ability to allocate resources for risk.
C.
sufficient time for monitoring and managing the risk effectively.
Answers
C.
sufficient time for monitoring and managing the risk effectively.
D.
risk communication and reporting skills to enable decision-making.
Answers
D.
risk communication and reporting skills to enable decision-making.
Suggested answer: B

Explanation:

Comprehensive and Detailed Explanation = The risk owner is the person or entity with the accountability and authority to manage a risk. The risk owner should have the decision-making authority and the ability to allocate resources for risk treatment and related control activities. The risk owner should also be responsible for monitoring and reporting on the risk, but these are not the most important considerations when assigning a risk owner. The risk owner may not have adequate knowledge of risk treatment and related control activities, but can delegate or consult with experts as needed. The risk owner should also have sufficient time for managing the risk effectively, but this is not a prerequisite for assigning a risk owner.

Reference =

CISM Review Manual 15th Edition, page 76

CISM Practice Quiz, question 4171

asked 01/10/2024
Emily Mangrum
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first