CGRC · Question #723
What is not a responsibility of the Risk Executive (Function) in an organization's ISCM? Response:
The correct answer is A. Participate in the configuration management process. This question asks to identify an activity that falls outside the typical responsibilities of the Risk Executive (Function) within an organization's Information Security Continuous Monitoring (ISCM) program.
Question
What is not a responsibility of the Risk Executive (Function) in an organization's ISCM? Response:
Options
- AParticipate in the configuration management process
- BReview status reports from the ISCM process as input to information security risk posture and risk
- COversee the organization's ISCM program
- DProvide input to mission/business process and information tier entities on ISCM strategy
How the community answered
(37 responses)- A95% (35)
- B3% (1)
- C3% (1)
Why each option
This question asks to identify an activity that falls outside the typical responsibilities of the Risk Executive (Function) within an organization's Information Security Continuous Monitoring (ISCM) program.
The Risk Executive (Function) operates at a strategic, enterprise-wide level, focusing on managing overall organizational risk and overseeing the ISCM program. Direct participation in operational configuration management processes is typically a responsibility of system administrators or information system owners, not the Risk Executive.
Reviewing status reports from the ISCM process is a core responsibility of the Risk Executive to assess the organization's risk posture and inform strategic decisions.
Overseeing the organization's ISCM program is a key strategic duty of the Risk Executive to ensure its effectiveness and alignment with risk management objectives.
Providing input on ISCM strategy to different organizational tiers is an important function of the Risk Executive to foster consistent and effective risk management across the enterprise.
Concept tested: Risk Executive responsibilities in ISCM
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137.pdf
Topics
Community Discussion
No community discussion yet for this question.