CAS-003 · Question #11
The risk subcommittee of a corporate board typically maintains a master register of the most prominent risks to the company. A centralized holistic view of risk is particularly important to the…
The correct answer is B. risks introduced by a system in one business unit can affect other business units in ways in which. A – No – “Risk” does not necessarily mean IT systems, the Risk committee addresses all forms of B – Yes – For example, one entity outsourcing the management of some systems that other entities may have strict controls over access (PII for example) C – No – The GC can…
Question
The risk subcommittee of a corporate board typically maintains a master register of the most prominent risks to the company. A centralized holistic view of risk is particularly important to the corporate Chief Information Security Officer (CISO) because:
Options
- AIT systems are maintained in silos to minimize interconnected risks and provide clear risk
- Brisks introduced by a system in one business unit can affect other business units in ways in which
- Ccorporate general counsel requires a single system boundary to determine overall corporate risk
- Dmajor risks identified by the subcommittee merit the prioritized allocation of scare funding to
How the community answered
(48 responses)- A10% (5)
- B81% (39)
- C6% (3)
- D2% (1)
Explanation
A – No – “Risk” does not necessarily mean IT systems, the Risk committee addresses all forms of B – Yes – For example, one entity outsourcing the management of some systems that other entities may have strict controls over access (PII for example) C – No – The GC can consolidate individual IT risks from the individual entities with their overall risk and then consolidate the entities for themselves. D – No – Prioritising risks is the job of the sub-committee, but does not require a CISO for this.
Topics
Community Discussion
No community discussion yet for this question.