ExamGecko
Question list
Search
Search

Question 461 - CISM discussion

Report
Export

A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?

A.
Security manager
Answers
A.
Security manager
B.
Chief information security officer (CISO)
Answers
B.
Chief information security officer (CISO)
C.
System administrator
Answers
C.
System administrator
D.
Business owner
Answers
D.
Business owner
Suggested answer: B

Explanation:

Verified Answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section Explanation:3.2.1.3, 'The appropriate risk treatment option is decided by the chief information security officer (CISO) or the designated risk owner.'

he CISM Review Manual, 15th Edition, Chapter 3, Section Explanation:3.2.1.3, 'The appropriate risk treatment option is decided by the chief information security officer (CISO) or the designated risk owner.'1

Comprehensive and Detailed Explanation: The CISO is the senior executive who is responsible for overseeing and managing the information security program of an organization. The CISO has the authority and expertise to assess the risks, determine the risk appetite and tolerance levels, and select the most suitable risk treatment options for each risk. The CISO also has the accountability and responsibility for implementing, monitoring, and reporting on the risk treatment activities.

asked 01/10/2024
Vincent Meuldijk
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first