nerdexam
Isaca

CISM · Question #117

Who should decide whether a specific control should be changed once risk is approved for mitigation?

The correct answer is C. Control owner. The control owner is responsible for the operational management and modification of specific security controls once a risk mitigation strategy is approved.

Submitted by jakub_pl· Apr 18, 2026Information Risk Management

Question

Who should decide whether a specific control should be changed once risk is approved for mitigation?

Options

  • ARisk owner
  • BData owner
  • CControl owner
  • DProcess owner

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    87% (40)
  • D
    4% (2)

Why each option

The control owner is responsible for the operational management and modification of specific security controls once a risk mitigation strategy is approved.

ARisk owner

The risk owner is responsible for the overall risk and deciding *how* to treat it (e.g., mitigate), but not the specific technical changes to a control.

BData owner

The data owner is responsible for the classification and protection requirements of data, not the specific technical changes to controls that protect it.

CControl ownerCorrect

The control owner is the individual or team accountable for the day-to-day operation, maintenance, and effectiveness of a particular security control. They possess the necessary technical expertise and authority to determine the specific changes needed to implement approved risk mitigation strategies for their assigned controls.

DProcess owner

The process owner is responsible for the overall business process, but not the detailed technical implementation or modification of individual security controls within that process.

Concept tested: Roles and responsibilities in risk management

Topics

#Control ownership#Risk mitigation#Roles and responsibilities#Information security controls

Community Discussion

No community discussion yet for this question.

Full CISM Practice