ExamGecko
Question list
Search
Search

Question 568 - CISM discussion

Report
Export

Of the following, who is BEST positioned to be accountable for risk acceptance decisions based on risk appetite?

A.
Information security manager
Answers
A.
Information security manager
B.
Chief risk officer (CRO)
Answers
B.
Chief risk officer (CRO)
C.
Information security steering committee
Answers
C.
Information security steering committee
D.
Risk owner
Answers
D.
Risk owner
Suggested answer: D

Explanation:

The risk owner is the best positioned to be accountable for risk acceptance decisions based on risk appetite, because the risk owner is the person or entity with the accountability and authority to manage a risk1.The risk owner is responsible for evaluating the risk level, comparing it with the risk appetite, and deciding whether to accept, avoid, transfer, or mitigate the risk2.The risk owner is also accountable for monitoring and reporting on the risk status and outcomes3. The information security manager, the chief risk officer (CRO), and the information security steering committee may have some roles and responsibilities in the risk management process, but they are not the primary accountable parties for risk acceptance decisions.

Reference= CISM Review Manual, 16th Edition, page 754; Risk Acceptance

asked 01/10/2024
dion alken
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first