CRISC · Question #344
The operational risk associated with attacks on a web application should be owned by the individual in charge of:
The correct answer is D. the business function. Operational risk, including that from web application attacks, should ultimately be owned by the business function because they are responsible for the business process the application supports and bear the consequences of disruptions.
Question
The operational risk associated with attacks on a web application should be owned by the individual in charge of:
Options
- Anetwork operations.
- Bthe cybersecurity function.
- Capplication development.
- Dthe business function.
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C7% (2)
- D86% (24)
Why each option
Operational risk, including that from web application attacks, should ultimately be owned by the business function because they are responsible for the business process the application supports and bear the consequences of disruptions.
Network operations manages network infrastructure, which is a component but not the ultimate owner of the application's operational risk.
The cybersecurity function advises on, manages, and mitigates security risks, but the ultimate ownership of the operational business risk lies with the business unit.
Application development is responsible for building and maintaining the application securely, but the operational risk of the application in production rests with the business function.
The business function, often represented by the business owner or product owner, is ultimately responsible for the operations, revenue, and reputation associated with the web application and the business process it enables. Therefore, they own the operational risk, including the impact of security incidents, and are responsible for defining the acceptable risk levels.
Concept tested: Operational risk ownership
Topics
Community Discussion
No community discussion yet for this question.