nerdexam
Isaca

CISM · Question #620

Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?

The correct answer is A. Risk owner. The risk owner is the individual who is accountable for managing a specific risk within their domain. They have both the authority and the organizational accountability to decide whether the current level of risk is acceptable or whether additional treatment is warranted. The IT

Submitted by satoshi_tk· Apr 18, 2026Information Security Risk Management

Question

Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?

Options

  • ARisk owner
  • BIT risk manager
  • CInformation security manager
  • DInternal auditor

How the community answered

(48 responses)
  • A
    94% (45)
  • B
    2% (1)
  • C
    2% (1)
  • D
    2% (1)

Explanation

The risk owner is the individual who is accountable for managing a specific risk within their domain. They have both the authority and the organizational accountability to decide whether the current level of risk is acceptable or whether additional treatment is warranted. The IT risk manager (B) and information security manager (C) provide analysis and recommendations, but they are advisory roles in this context. The internal auditor (D) evaluates and reports on controls but has no authority to direct risk treatment decisions. Accountability for the risk - and therefore the decision - rests with the risk owner.

Topics

#Risk ownership#Risk treatment#Roles and responsibilities#Risk management process

Community Discussion

No community discussion yet for this question.

Full CISM Practice