nerdexam
(ISC)2

CGRC · Question #445

In performing ongoing risk determination and acceptance; the AO consults with the CISO and Risk _______________ to determine whether current system risk is acceptable, provides appropriate direction t

The correct answer is A. Executive. When determining and accepting ongoing system risk, the Authorizing Official (AO) consults with the CISO and the Risk Executive to ensure decisions align with organizational risk tolerance.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

In performing ongoing risk determination and acceptance; the AO consults with the CISO and Risk _______________ to determine whether current system risk is acceptable, provides appropriate direction to the system owner. Response:

Options

  • AExecutive
  • BDirective
  • CRegulation
  • DPolicy

How the community answered

(42 responses)
  • A
    93% (39)
  • C
    2% (1)
  • D
    5% (2)

Why each option

When determining and accepting ongoing system risk, the Authorizing Official (AO) consults with the CISO and the Risk Executive to ensure decisions align with organizational risk tolerance.

AExecutiveCorrect

The Risk Executive (or Risk Executive Function) is a senior-level individual or group within an organization responsible for providing an enterprise-wide perspective on risk management. The AO consults with the CISO and the Risk Executive to ensure that risk decisions align with organizational priorities and risk tolerance, especially regarding ongoing risk determination and acceptance.

BDirective

A directive is an instruction or order; the AO would consult with a person or group for expertise, not a directive itself.

CRegulation

A regulation is a rule or law; while important for context, the AO consults people for risk determination, not the regulation directly.

DPolicy

A policy is a set of rules or principles; similar to regulations and directives, the AO consults with individuals who interpret and apply policies, not the policy document itself.

Concept tested: Roles in NIST Risk Management Framework (RMF)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Risk Management#Organizational Roles#Risk Acceptance#Authorizing Official (AO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice