nerdexam
Isaca

CISM · Question #486

An information security manager has completed a risk assessment for a business information system. Of the following, who is BEST positioned to decide on the implementation of mitigating controls?

The correct answer is A. System owner. System Owner is best positioned to decide on implementing mitigating controls because they have both the authority and accountability for the system's operation, budget, and risk tolerance - making them the decision-maker for accepting, transferring, or mitigating risks…

Submitted by khalil_dz· Apr 18, 2026Information Security Risk Management

Question

An information security manager has completed a risk assessment for a business information system. Of the following, who is BEST positioned to decide on the implementation of mitigating controls?

Options

  • ASystem owner
  • BChief information officer (CIO)
  • CRisk manager
  • DSystem administrator

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    13% (4)
  • C
    3% (1)
  • D
    3% (1)

Explanation

System Owner is best positioned to decide on implementing mitigating controls because they have both the authority and accountability for the system's operation, budget, and risk tolerance - making them the decision-maker for accepting, transferring, or mitigating risks identified in the assessment.

Why the distractors are wrong:

  • B (CIO): The CIO sets strategic IT direction organization-wide but typically delegates system-level risk decisions to system owners - too high-level for this specific call.
  • C (Risk manager): The risk manager identifies and assesses risk (as done here), but deciding what to do about it is an ownership decision, not a risk function responsibility.
  • D (System administrator): The sysadmin implements controls once a decision is made, but lacks the authority and budget control to decide whether mitigation is warranted.

Memory tip: Think "ownership = accountability = decision authority." The person who owns the system owns the risk decision. The risk manager advises, the sysadmin executes, the CIO oversees - but only the system owner can commit to a control investment.

Topics

#Risk treatment decision#System owner accountability#Mitigating controls#Roles and responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice