CISM · Question #203
Of the following, who is BEST suited to own the risk discovered in an application?
The correct answer is C. System owner. Risk ownership belongs with the person who owns the asset creating the risk. The system owner has accountability for the application, understands its business purpose, has authority over it, and is ultimately responsible for decisions about its operation and acceptable risk level
Question
Of the following, who is BEST suited to own the risk discovered in an application?
Options
- AInformation security manager
- BSenior management
- CSystem owner
- DControl owner
How the community answered
(36 responses)- A3% (1)
- B6% (2)
- C89% (32)
- D3% (1)
Explanation
Risk ownership belongs with the person who owns the asset creating the risk. The system owner has accountability for the application, understands its business purpose, has authority over it, and is ultimately responsible for decisions about its operation and acceptable risk levels. The information security manager (A) advises on risk but does not own business assets. Senior management (B) is too removed from the specific system to own application-level risks. The control owner (D) is responsible for maintaining a specific control, not for the overall risk associated with the system. Risk ownership must reside with the person who controls the asset.
Topics
Community Discussion
No community discussion yet for this question.