Certified Information Security Manager CISM · Free Practice Question Easy

Question 42

In a properly functioning risk management program, which party assumes cyber risk?
  • A CISO
  • B Relevant business unit leader
  • C Legal
  • D Customer
Reveal correct answer

Correct answer: B

Explanation

Correct Answer:

Relevant business unit leader is correct. In a properly functioning risk management program, a business unit leader should be accepting risks associated with various business activities that the business leader wants to undertake.

Incorrect Answers:

CISO is incorrect because the CISO would rarely accept risk; the CISO should be acting as a risk facilitator.

Legal is incorrect because the legal department would not accept cyber risk.

Customer is incorrect because this is not the best choice.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need