CRISC · Question #637
Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?
The correct answer is A. Risk owner. When an IT stakeholder operates a key control to address a risk scenario, the risk owner is ultimately accountable for the overall risk management process.
Question
Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?
Options
- ARisk owner
- BIT manager
- CSystem owner
- DData custodian
How the community answered
(53 responses)- A91% (48)
- B6% (3)
- C2% (1)
- D2% (1)
Why each option
When an IT stakeholder operates a key control to address a risk scenario, the risk owner is ultimately accountable for the overall risk management process.
The risk owner is a designated individual or entity responsible for managing a specific risk, including ensuring that appropriate controls are in place, effective, and monitored. While an IT stakeholder may *operate* a control, the risk owner retains ultimate accountability for the risk and its management process.
An IT manager might be responsible for the IT operations, including the control's implementation, but accountability for the *risk itself* lies with the risk owner.
A system owner is responsible for a specific system, and may operate controls within that system, but the accountability for the broader risk associated with a scenario falls to the risk owner.
A data custodian is responsible for the care and management of data, which is distinct from the overall accountability for managing a risk scenario.
Concept tested: Risk ownership and accountability
Topics
Community Discussion
No community discussion yet for this question.