Certified Information Security Manager CISM · Free Practice Question Easy
Question 42
In a properly functioning risk management program, which party assumes cyber risk?
- A CISO
- B Relevant business unit leader
- C Legal
- D Customer
Reveal correct answer
Correct answer: B
Explanation
Correct Answer:
Relevant business unit leader is correct. In a properly functioning risk management program, a business unit leader should be accepting risks associated with various business activities that the business leader wants to undertake.
Incorrect Answers:
CISO is incorrect because the CISO would rarely accept risk; the CISO should be acting as a risk facilitator.
Legal is incorrect because the legal department would not accept cyber risk.
Customer is incorrect because this is not the best choice.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
