CRISC · Question #28
An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?
The correct answer is A. IT risk practitioner. While multiple parties are involved in third-party risk management, the IT risk practitioner is accountable for ensuring that risk responses are implemented following an assessment of a service provider. This role is responsible for overseeing the risk management process, trackin
Question
An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?
Options
- AIT risk practitioner
- BThird -partf3ecurity team
- CThe relationship owner
- DLegal representation of the business
How the community answered
(17 responses)- A71% (12)
- B18% (3)
- C6% (1)
- D6% (1)
Why each option
While multiple parties are involved in third-party risk management, the IT risk practitioner is accountable for ensuring that risk responses are implemented following an assessment of a service provider. This role is responsible for overseeing the risk management process, tracking, and verifying the execution of agreed-upon mitigation strategies.
The IT risk practitioner, or the individual/team assigned the overall responsibility for managing technology-related risks, is ultimately accountable for ensuring that risk responses identified during a service provider assessment are actually implemented. They are typically responsible for tracking, monitoring, and validating that the agreed-upon actions are carried out, even if the execution is delegated to others.
The third-party security team is responsible for implementing controls within their own organization, but the *client's* IT risk practitioner is accountable for ensuring those responses are executed and effective from the client's perspective.
The relationship owner (e.g., business owner or vendor manager) is crucial for managing the overall relationship and facilitating communication, but they may not have the specific technical expertise or direct accountability for the *implementation* of IT risk responses.
Legal representation of the business provides guidance on contractual obligations and legal risks but is not typically accountable for the operational implementation of technical risk responses.
Concept tested: Third-party risk response accountability
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.