nerdexam
Isaca

CISM · Question #138

An organization has implemented a new email filter to mitigate risk associated with its email system. Who is BEST suited to be the control owner?

The correct answer is D. Head of information security. The Head of information security is best suited to be the control owner for an email filter, as they are ultimately responsible for the overall security posture and risk mitigation within the organization.

Submitted by anna_se· Apr 18, 2026Information Security Governance

Question

An organization has implemented a new email filter to mitigate risk associated with its email system. Who is BEST suited to be the control owner?

Options

  • AHead of IT department
  • BHead of compliance
  • CHead of corporate communications
  • DHead of information security

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    14% (3)
  • D
    71% (15)

Why each option

The Head of information security is best suited to be the control owner for an email filter, as they are ultimately responsible for the overall security posture and risk mitigation within the organization.

AHead of IT department

The Head of the IT department might be responsible for the *operation* of the email filter, but the *ownership* of the security control itself typically rests with information security.

BHead of compliance

The Head of compliance ensures adherence to regulations but is not typically the owner of specific technical security controls.

CHead of corporate communications

The Head of corporate communications uses the email system but is not responsible for its underlying security controls.

DHead of information securityCorrect

The Head of information security is responsible for managing and overseeing the organization's information security program, including the implementation and effectiveness of security controls like an email filter. As the control owner, this individual is accountable for ensuring the filter adequately mitigates email-related risks and aligns with the organization's security policies.

Concept tested: Information security roles and responsibilities

Topics

#Control Ownership#Roles and Responsibilities#Risk Mitigation#Information Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice