nerdexam
Isaca

CISM · Question #913

After performing a risk assessment, an information security manager identified IT issues with a third-party vendor used by the finance department. Of the following, who is BEST positioned to define…

The correct answer is B. Head of finance. Risk ownership follows business ownership. The Head of Finance owns the business relationship with this vendor and is accountable for the associated risks and outcomes. Risk treatment decisions - accept, mitigate, transfer, or avoid - must be made by the business owner who…

Submitted by krish.m· Apr 18, 2026Information Security Risk Management

Question

After performing a risk assessment, an information security manager identified IT issues with a third-party vendor used by the finance department. Of the following, who is BEST positioned to define the risk treatment plans?

Options

  • AHead of IT
  • BHead of finance
  • CHead of vendor management
  • DHead of information security

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    85% (23)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Risk ownership follows business ownership. The Head of Finance owns the business relationship with this vendor and is accountable for the associated risks and outcomes. Risk treatment decisions - accept, mitigate, transfer, or avoid - must be made by the business owner who understands the operational context, business value of the vendor relationship, and is ultimately accountable for the risk. The Head of IT (A) handles technical execution, Head of Vendor Management (C) manages contracts, and Head of Information Security (D) identifies and advises on risk, but none of them own this business risk the way the finance lead does.

Topics

#Risk Ownership#Risk Treatment#Third-Party Risk#Roles and Responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice