CISM · Question #913
After performing a risk assessment, an information security manager identified IT issues with a third-party vendor used by the finance department. Of the following, who is BEST positioned to define…
The correct answer is B. Head of finance. Risk ownership follows business ownership. The Head of Finance owns the business relationship with this vendor and is accountable for the associated risks and outcomes. Risk treatment decisions - accept, mitigate, transfer, or avoid - must be made by the business owner who…
Question
After performing a risk assessment, an information security manager identified IT issues with a third-party vendor used by the finance department. Of the following, who is BEST positioned to define the risk treatment plans?
Options
- AHead of IT
- BHead of finance
- CHead of vendor management
- DHead of information security
How the community answered
(27 responses)- A7% (2)
- B85% (23)
- C4% (1)
- D4% (1)
Explanation
Risk ownership follows business ownership. The Head of Finance owns the business relationship with this vendor and is accountable for the associated risks and outcomes. Risk treatment decisions - accept, mitigate, transfer, or avoid - must be made by the business owner who understands the operational context, business value of the vendor relationship, and is ultimately accountable for the risk. The Head of IT (A) handles technical execution, Head of Vendor Management (C) manages contracts, and Head of Information Security (D) identifies and advises on risk, but none of them own this business risk the way the finance lead does.
Topics
Community Discussion
No community discussion yet for this question.