Certified Information Security Manager CISM · Free Practice Question Easy

Question 24

A security governance council is unable to assign an owner to a specific risk. How should the council proceed?
  • A

    Assign the risk to the entire governance council.

  • B

    Assign the risk to the executive responsible for the relevant business activity.

  • C

    Mark the risk as having no owner.

  • D

    Assign the risk to the CISO.

Reveal correct answer

Correct answer: B

Explanation

Correct Answer:

"Assign the risk to the executive responsible for the relevant business activity." is correct. Every risk needs an owner; the best choice here is to assign the risk to the executive responsible for the business activity that the risk is associated with.

Incorrect Answers:

"Assign the risk to the CISO." is incorrect because the CISO should not be a risk owner (except in narrow circumstances under the CISO’s direct control, usually in the CISO’s department operations).

"Mark the risk as having no owner." and "Assign the risk to the entire governance council." are incorrect because they would result in no one individual being accountable to make risk decisions.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need