CISM · Question #117
Who should decide whether a specific control should be changed once risk is approved for mitigation?
The correct answer is C. Control owner. The control owner is responsible for the operational management and modification of specific security controls once a risk mitigation strategy is approved.
Question
Who should decide whether a specific control should be changed once risk is approved for mitigation?
Options
- ARisk owner
- BData owner
- CControl owner
- DProcess owner
How the community answered
(46 responses)- A2% (1)
- B7% (3)
- C87% (40)
- D4% (2)
Why each option
The control owner is responsible for the operational management and modification of specific security controls once a risk mitigation strategy is approved.
The risk owner is responsible for the overall risk and deciding *how* to treat it (e.g., mitigate), but not the specific technical changes to a control.
The data owner is responsible for the classification and protection requirements of data, not the specific technical changes to controls that protect it.
The control owner is the individual or team accountable for the day-to-day operation, maintenance, and effectiveness of a particular security control. They possess the necessary technical expertise and authority to determine the specific changes needed to implement approved risk mitigation strategies for their assigned controls.
The process owner is responsible for the overall business process, but not the detailed technical implementation or modification of individual security controls within that process.
Concept tested: Roles and responsibilities in risk management
Topics
Community Discussion
No community discussion yet for this question.