CISM · Question #767
Of the following, who is BEST positioned to approve specific information security risk treatment options?
The correct answer is A. Risk owner. The risk owner is best positioned to approve specific information security risk treatment options because they are accountable for managing the risk within their area of responsibility. They understand the business context and can decide whether to accept, mitigate, transfer, or
Question
Of the following, who is BEST positioned to approve specific information security risk treatment options?
Options
- ARisk owner
- BInformation security manager
- CHead of risk management
- DSenior management
How the community answered
(29 responses)- A86% (25)
- B3% (1)
- C7% (2)
- D3% (1)
Explanation
The risk owner is best positioned to approve specific information security risk treatment options because they are accountable for managing the risk within their area of responsibility. They understand the business context and can decide whether to accept, mitigate, transfer, or avoid the risk in line with organizational risk tolerance.
Topics
Community Discussion
No community discussion yet for this question.