nerdexam
Isaca

CISM · Question #203

Of the following, who is BEST suited to own the risk discovered in an application?

The correct answer is C. System owner. Risk ownership belongs with the person who owns the asset creating the risk. The system owner has accountability for the application, understands its business purpose, has authority over it, and is ultimately responsible for decisions about its operation and acceptable risk level

Submitted by saadiq_pk· Apr 18, 2026Information Security Risk Management

Question

Of the following, who is BEST suited to own the risk discovered in an application?

Options

  • AInformation security manager
  • BSenior management
  • CSystem owner
  • DControl owner

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    89% (32)
  • D
    3% (1)

Explanation

Risk ownership belongs with the person who owns the asset creating the risk. The system owner has accountability for the application, understands its business purpose, has authority over it, and is ultimately responsible for decisions about its operation and acceptable risk levels. The information security manager (A) advises on risk but does not own business assets. Senior management (B) is too removed from the specific system to own application-level risks. The control owner (D) is responsible for maintaining a specific control, not for the overall risk associated with the system. Risk ownership must reside with the person who controls the asset.

Topics

#Risk ownership#Roles and responsibilities#System owner#Application security

Community Discussion

No community discussion yet for this question.

Full CISM Practice