CRISC · Question #537
A penetration testing team discovered an ineffectively designed access control. Who is responsible for ensuring the control design gap is remediated?
The correct answer is A. Control owner. The control owner is ultimately accountable for the design, implementation, and effectiveness of a specific control and is therefore responsible for remediating any identified design gaps.
Question
A penetration testing team discovered an ineffectively designed access control. Who is responsible for ensuring the control design gap is remediated?
Options
- AControl owner
- BRisk owner
- CIT security manager
- DControl operator
How the community answered
(43 responses)- A91% (39)
- B5% (2)
- C2% (1)
- D2% (1)
Why each option
The control owner is ultimately accountable for the design, implementation, and effectiveness of a specific control and is therefore responsible for remediating any identified design gaps.
The control owner is the individual or group ultimately accountable for the effective design and operation of a specific control, including its remediation if found to be ineffective. They ensure the control meets its objectives and aligns with the organization's risk management framework.
The risk owner is responsible for managing the overall risk, but the control owner is specifically accountable for the controls that mitigate that risk.
The IT security manager may oversee security operations and advise on remediation, but the ultimate accountability for the specific control lies with its owner.
The control operator executes the control's procedures, but they are not typically responsible for redesigning or ensuring the overall effectiveness of the control's design.
Concept tested: Control ownership responsibilities
Topics
Community Discussion
No community discussion yet for this question.