CISM · Question #982
As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?
The correct answer is B. The risk owner has the authority to take action on the risk. A risk owner must have the organizational authority to approve remediation budgets, mandate corrective actions, and hold accountable parties responsible. Without authority, a risk owner is merely a record-keeper - they cannot actually reduce or transfer the risk. Updating the…
Question
As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?
Options
- AThe risk owner is able to make timely updates to the risk register.
- BThe risk owner has the authority to take action on the risk.
- CThe risk owner is able to reassess the risk following remediation.
- DThe risk owner also owns the associated control that failed.
How the community answered
(29 responses)- A14% (4)
- B72% (21)
- C7% (2)
- D7% (2)
Explanation
A risk owner must have the organizational authority to approve remediation budgets, mandate corrective actions, and hold accountable parties responsible. Without authority, a risk owner is merely a record-keeper - they cannot actually reduce or transfer the risk. Updating the risk register (A) and reassessing risk after remediation (C) are administrative tasks that do not require ownership-level authority. Owning the failed control (D) may create a conflict of interest, as the person may be motivated to downplay the risk rather than address it objectively.
Topics
Community Discussion
No community discussion yet for this question.