ExamGecko
Question list
Search
Search

Question 550 - CISM discussion

Report
Export

Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?

A.
Information security manager
Answers
A.
Information security manager
B.
IT risk manager
Answers
B.
IT risk manager
C.
Internal auditor
Answers
C.
Internal auditor
D.
Risk owner
Answers
D.
Risk owner
Suggested answer: D

Explanation:

The risk owner is the person who has the authority and accountability to make decisions about the risk, including whether to accept, avoid, transfer, or mitigate it. The risk owner is also responsible for implementing and monitoring the risk treatment plan and reporting on the risk status. The risk owner is usually the business process owner or the information owner of the asset affected by the risk. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Arkadiusz Skopinski
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first