nerdexam
EC-Council

712-50 · Question #298

Acceptable levels of information security risk tolerance in an organization should be determined by?

The correct answer is C. CEO and board of director. C is correct because risk tolerance is a governance decision that sets organizational strategy - it belongs to the CEO and board of directors, who are ultimately accountable to shareholders and stakeholders for the organization's risk posture. They define how much risk the…

Governance (Policy, Legal & Compliance)

Question

Acceptable levels of information security risk tolerance in an organization should be determined by?

Options

  • ACorporate legal counsel
  • BCISO with reference to the company goals
  • CCEO and board of director
  • DCorporate compliance committee

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (24)
  • D
    3% (1)

Explanation

C is correct because risk tolerance is a governance decision that sets organizational strategy - it belongs to the CEO and board of directors, who are ultimately accountable to shareholders and stakeholders for the organization's risk posture. They define how much risk the organization is willing to accept, which then cascades down to security programs.

Why the distractors are wrong:

  • A (Legal counsel) - Legal advises on compliance and liability but doesn't set strategic risk appetite; they're consultants, not decision-makers on risk tolerance.
  • B (CISO) - The CISO implements the risk strategy and informs the board, but doesn't have the authority or organizational accountability to set enterprise-wide risk tolerance.
  • D (Compliance committee) - Compliance committees ensure adherence to regulations, which is a floor (minimum requirements), not the same as setting the organization's broader risk appetite.

Memory tip: Think "top of the house owns the risk." Risk tolerance is a business strategy decision requiring the highest level of accountability - the board sets it, executives execute it, and security professionals manage within it. If you see "risk tolerance" or "risk appetite" on the exam, the answer almost always points to executive leadership or the board.

Topics

#Risk Tolerance#Governance#Executive Oversight#Risk Appetite

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice