nerdexam
Isaca

CISM · Question #432

Of the following, who is BEST positioned to assume ownership of a security control to prevent fraudulent activity?

The correct answer is C. Process owner. The process owner is best positioned to assume ownership of a security control to prevent fraudulent activity because they are responsible for the day-to-day operations and management of business processes. They understand how the process functions, where vulnerabilities may exis

Submitted by andreas_gr· Apr 18, 2026Information Security Governance

Question

Of the following, who is BEST positioned to assume ownership of a security control to prevent fraudulent activity?

Options

  • AInternal audit
  • BInformation owner
  • CProcess owner
  • DInformation security manager

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    10% (6)
  • C
    83% (50)
  • D
    5% (3)

Explanation

The process owner is best positioned to assume ownership of a security control to prevent fraudulent activity because they are responsible for the day-to-day operations and management of business processes. They understand how the process functions, where vulnerabilities may exist, and how controls can be effectively implemented without disrupting business operations. While internal audit, information owners, and security managers play supporting roles, the process owner is directly responsible for operational integrity and fraud prevention.

Topics

#Control ownership#Roles and responsibilities#Fraud prevention#Process management

Community Discussion

No community discussion yet for this question.

Full CISM Practice