nerdexam
Isaca

CISM · Question #767

Of the following, who is BEST positioned to approve specific information security risk treatment options?

The correct answer is A. Risk owner. The risk owner is best positioned to approve specific information security risk treatment options because they are accountable for managing the risk within their area of responsibility. They understand the business context and can decide whether to accept, mitigate, transfer, or

Submitted by the_admin· Apr 18, 2026Information Security Risk Management

Question

Of the following, who is BEST positioned to approve specific information security risk treatment options?

Options

  • ARisk owner
  • BInformation security manager
  • CHead of risk management
  • DSenior management

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    3% (1)
  • C
    7% (2)
  • D
    3% (1)

Explanation

The risk owner is best positioned to approve specific information security risk treatment options because they are accountable for managing the risk within their area of responsibility. They understand the business context and can decide whether to accept, mitigate, transfer, or avoid the risk in line with organizational risk tolerance.

Topics

#Risk ownership#Risk treatment#Roles and responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice