CISM · Question #264
Which of the following is MOST relevant for an information security manager to communicate to business units?
The correct answer is C. Risk ownership. Risk ownership is the most important concept for an information security manager to communicate to business units because it establishes accountability - business units own the risks associated with their operations, not the security team. The security function advises…
Question
Which of the following is MOST relevant for an information security manager to communicate to business units?
Options
- AVulnerability assessments
- BThreat intelligence reports
- CRisk ownership
- DBusiness impact analysis (BIA)
How the community answered
(19 responses)- A16% (3)
- B5% (1)
- C47% (9)
- D32% (6)
Explanation
Risk ownership is the most important concept for an information security manager to communicate to business units because it establishes accountability - business units own the risks associated with their operations, not the security team. The security function advises, facilitates, and provides tools, but business managers must accept and manage risk within their domains. Vulnerability assessments (A) and threat intelligence reports (B) are technical outputs more relevant to security operations. A BIA (D) is an analytical tool, typically produced collaboratively with business units rather than communicated to them. Without clear risk ownership, governance breaks down and risk decisions are made without accountability.
Topics
Community Discussion
No community discussion yet for this question.