ExamGecko
Question list
Search
Search

Question 581 - CISM discussion

Report
Export

An organization's information security team presented the risk register at a recent information security steering committee meeting. Which of the following should be of MOST concern to the committee?

A.
No owners were identified for some risks.
Answers
A.
No owners were identified for some risks.
B.
Business applications had the highest number of risks.
Answers
B.
Business applications had the highest number of risks.
C.
Risk mitigation action plans had no timelines.
Answers
C.
Risk mitigation action plans had no timelines.
D.
Risk mitigation action plan milestones were delayed.
Answers
D.
Risk mitigation action plan milestones were delayed.
Suggested answer: A

Explanation:

The most concerning issue for the information security steering committee should be that no owners were identified for some risks in the risk register. This means that there is no clear accountability and responsibility for managing and mitigating those risks, and that the risks may not be properly addressed or monitored. The risk owners are the persons who have the authority and ability to implement the risk treatment options and to accept the residual risk. The risk owners should be identified and assigned for each risk in the risk register, and they should report the status and progress of the risk management activities to the information security steering committee.

Reference= CISM Review Manual, 16th Edition eBook1, Chapter 2: Information Risk Management, Section: Risk Management, Subsection: Risk Register, Page 104.

asked 01/10/2024
Brandon Garner
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first