nerdexam
Isaca

CISM · Question #607

Who is BEST positioned to take ownership of critical IT security risks identified in an application?

The correct answer is C. Business application owner. The business application owner is best positioned to take ownership of critical IT security risks because they are accountable for the application's use, data, and impact on business operations, and are responsible for risk decisions.

Submitted by cyberguy42· Apr 18, 2026Information Security Governance

Question

Who is BEST positioned to take ownership of critical IT security risks identified in an application?

Options

  • AChief information security officer (CISO)
  • BLead application developer
  • CBusiness application owner
  • DChief information officer (CIO)

How the community answered

(47 responses)
  • A
    17% (8)
  • B
    6% (3)
  • C
    72% (34)
  • D
    4% (2)

Explanation

The business application owner is best positioned to take ownership of critical IT security risks because they are accountable for the application's use, data, and impact on business operations, and are responsible for risk decisions.

Topics

#Risk Ownership#Application Security#Roles & Responsibilities#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice