nerdexam
Isaca

CRISC · Question #344

The operational risk associated with attacks on a web application should be owned by the individual in charge of:

The correct answer is D. the business function. Operational risk, including that from web application attacks, should ultimately be owned by the business function because they are responsible for the business process the application supports and bear the consequences of disruptions.

Submitted by manish99· Apr 18, 2026Governance

Question

The operational risk associated with attacks on a web application should be owned by the individual in charge of:

Options

  • Anetwork operations.
  • Bthe cybersecurity function.
  • Capplication development.
  • Dthe business function.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    7% (2)
  • D
    86% (24)

Why each option

Operational risk, including that from web application attacks, should ultimately be owned by the business function because they are responsible for the business process the application supports and bear the consequences of disruptions.

Anetwork operations.

Network operations manages network infrastructure, which is a component but not the ultimate owner of the application's operational risk.

Bthe cybersecurity function.

The cybersecurity function advises on, manages, and mitigates security risks, but the ultimate ownership of the operational business risk lies with the business unit.

Capplication development.

Application development is responsible for building and maintaining the application securely, but the operational risk of the application in production rests with the business function.

Dthe business function.Correct

The business function, often represented by the business owner or product owner, is ultimately responsible for the operations, revenue, and reputation associated with the web application and the business process it enables. Therefore, they own the operational risk, including the impact of security incidents, and are responsible for defining the acceptable risk levels.

Concept tested: Operational risk ownership

Topics

#Risk ownership#Operational risk#Business accountability#CRISC principles

Community Discussion

No community discussion yet for this question.

Full CRISC Practice