nerdexam
Isaca

CISM · Question #982

As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?

The correct answer is B. The risk owner has the authority to take action on the risk. A risk owner must have the organizational authority to approve remediation budgets, mandate corrective actions, and hold accountable parties responsible. Without authority, a risk owner is merely a record-keeper - they cannot actually reduce or transfer the risk. Updating the…

Submitted by marco_it· Apr 18, 2026Information Security Risk Management

Question

As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?

Options

  • AThe risk owner is able to make timely updates to the risk register.
  • BThe risk owner has the authority to take action on the risk.
  • CThe risk owner is able to reassess the risk following remediation.
  • DThe risk owner also owns the associated control that failed.

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    72% (21)
  • C
    7% (2)
  • D
    7% (2)

Explanation

A risk owner must have the organizational authority to approve remediation budgets, mandate corrective actions, and hold accountable parties responsible. Without authority, a risk owner is merely a record-keeper - they cannot actually reduce or transfer the risk. Updating the risk register (A) and reassessing risk after remediation (C) are administrative tasks that do not require ownership-level authority. Owning the failed control (D) may create a conflict of interest, as the person may be motivated to downplay the risk rather than address it objectively.

Topics

#Risk Management#Risk Ownership#Accountability#Risk Response

Community Discussion

No community discussion yet for this question.

Full CISM Practice