nerdexam
Isaca

CISM · Question #264

Which of the following is MOST relevant for an information security manager to communicate to business units?

The correct answer is C. Risk ownership. Risk ownership is the most important concept for an information security manager to communicate to business units because it establishes accountability - business units own the risks associated with their operations, not the security team. The security function advises…

Submitted by fatema_kw· Apr 18, 2026Information Security Risk Management

Question

Which of the following is MOST relevant for an information security manager to communicate to business units?

Options

  • AVulnerability assessments
  • BThreat intelligence reports
  • CRisk ownership
  • DBusiness impact analysis (BIA)

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    5% (1)
  • C
    47% (9)
  • D
    32% (6)

Explanation

Risk ownership is the most important concept for an information security manager to communicate to business units because it establishes accountability - business units own the risks associated with their operations, not the security team. The security function advises, facilitates, and provides tools, but business managers must accept and manage risk within their domains. Vulnerability assessments (A) and threat intelligence reports (B) are technical outputs more relevant to security operations. A BIA (D) is an analytical tool, typically produced collaboratively with business units rather than communicated to them. Without clear risk ownership, governance breaks down and risk decisions are made without accountability.

Topics

#Risk Ownership#Business Alignment#Stakeholder Communication#Information Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice