nerdexam
Isaca

CISM · Question #136

It is MOST important that risk owners understand they are accountable for:

The correct answer is D. overseeing and monitoring the effectiveness of controls associated with the risk. A risk owner is the individual accountable for ensuring that a given risk is properly managed within their domain. Their core accountability is overseeing and monitoring the effectiveness of controls associated with that risk-they own the risk, so they own the assurance that…

Submitted by emma.c· Apr 18, 2026Information Security Risk Management

Question

It is MOST important that risk owners understand they are accountable for:

Options

  • Acollaborating with stakeholders to evaluate the effectiveness of controls associated with the risk.
  • Breporting risk metrics and control compliance status to the information security manager.
  • Cescalating control deficiencies associated with the risk to the steering committee for decision
  • Doverseeing and monitoring the effectiveness of controls associated with the risk.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    8% (3)
  • D
    86% (32)

Explanation

A risk owner is the individual accountable for ensuring that a given risk is properly managed within their domain. Their core accountability is overseeing and monitoring the effectiveness of controls associated with that risk-they own the risk, so they own the assurance that the risk is being adequately controlled. Collaborating with stakeholders to evaluate controls (A) is an activity that supports this accountability but isn't the accountability itself. Reporting metrics to the security manager (B) is a supporting communication activity. Escalating deficiencies to the steering committee (C) is a specific escalation activity, not the overarching accountability. Oversight and monitoring of control effectiveness is the defining responsibility.

Topics

#Risk Owner#Accountability#Control Effectiveness#Risk Oversight

Community Discussion

No community discussion yet for this question.

Full CISM Practice