nerdexam
(ISC)2

CGRC · Question #723

What is not a responsibility of the Risk Executive (Function) in an organization's ISCM? Response:

The correct answer is A. Participate in the configuration management process. This question asks to identify an activity that falls outside the typical responsibilities of the Risk Executive (Function) within an organization's Information Security Continuous Monitoring (ISCM) program.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What is not a responsibility of the Risk Executive (Function) in an organization's ISCM? Response:

Options

  • AParticipate in the configuration management process
  • BReview status reports from the ISCM process as input to information security risk posture and risk
  • COversee the organization's ISCM program
  • DProvide input to mission/business process and information tier entities on ISCM strategy

How the community answered

(37 responses)
  • A
    95% (35)
  • B
    3% (1)
  • C
    3% (1)

Why each option

This question asks to identify an activity that falls outside the typical responsibilities of the Risk Executive (Function) within an organization's Information Security Continuous Monitoring (ISCM) program.

AParticipate in the configuration management processCorrect

The Risk Executive (Function) operates at a strategic, enterprise-wide level, focusing on managing overall organizational risk and overseeing the ISCM program. Direct participation in operational configuration management processes is typically a responsibility of system administrators or information system owners, not the Risk Executive.

BReview status reports from the ISCM process as input to information security risk posture and risk

Reviewing status reports from the ISCM process is a core responsibility of the Risk Executive to assess the organization's risk posture and inform strategic decisions.

COversee the organization's ISCM program

Overseeing the organization's ISCM program is a key strategic duty of the Risk Executive to ensure its effectiveness and alignment with risk management objectives.

DProvide input to mission/business process and information tier entities on ISCM strategy

Providing input on ISCM strategy to different organizational tiers is an important function of the Risk Executive to foster consistent and effective risk management across the enterprise.

Concept tested: Risk Executive responsibilities in ISCM

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf

Topics

#Risk Executive#ISCM#Roles and Responsibilities#Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice