CISM · Question #620
Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?
The correct answer is A. Risk owner. The risk owner is the individual who is accountable for managing a specific risk within their domain. They have both the authority and the organizational accountability to decide whether the current level of risk is acceptable or whether additional treatment is warranted. The IT
Question
Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?
Options
- ARisk owner
- BIT risk manager
- CInformation security manager
- DInternal auditor
How the community answered
(48 responses)- A94% (45)
- B2% (1)
- C2% (1)
- D2% (1)
Explanation
The risk owner is the individual who is accountable for managing a specific risk within their domain. They have both the authority and the organizational accountability to decide whether the current level of risk is acceptable or whether additional treatment is warranted. The IT risk manager (B) and information security manager (C) provide analysis and recommendations, but they are advisory roles in this context. The internal auditor (D) evaluates and reports on controls but has no authority to direct risk treatment decisions. Accountability for the risk - and therefore the decision - rests with the risk owner.
Topics
Community Discussion
No community discussion yet for this question.