CRISC · Question #214
Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application'?
The correct answer is C. The business process owner. When defining a risk profile for a new third-party application, the business process owner is the most crucial stakeholder due to their comprehensive understanding of the application's operational context.
Question
Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application'?
Options
- AThe third-party risk manager
- BThe application vendor
- CThe business process owner
- DThe information security manager
How the community answered
(34 responses)- A6% (2)
- B18% (6)
- C74% (25)
- D3% (1)
Why each option
When defining a risk profile for a new third-party application, the business process owner is the most crucial stakeholder due to their comprehensive understanding of the application's operational context.
The third-party risk manager focuses on vendor risk and contractual aspects but may lack the granular operational insight of the business process owner.
The application vendor provides technical specifications but lacks the organizational-specific business context needed for a comprehensive risk profile.
The business process owner possesses the deepest insight into how the application will be used, its criticality to business functions, the types of data it will process, and the potential operational and business impacts of its failure or compromise, which is essential for an accurate risk profile. They can articulate the true value and sensitivity within the business context.
The information security manager is critical for security aspects but the overall risk profile also encompasses broader business, operational, and compliance risks best articulated by the business process owner.
Concept tested: Stakeholder identification for risk profiling
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.