Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 2 Question 114 Discussion

A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?
B) Chief information security officer (CISO)
A) Security manager
C) System administrator
D) Business owner

Isaca CISM Exam - Topic 2 Question 114 Discussion

Actual exam question for Isaca's CISM exam
Question #: 114
Topic #: 2
[All CISM Questions]

A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?

Show Suggested Answer Hide Answer
Suggested Answer: B

Verified Answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.3, 'The appropriate risk treatment option is decided by the chief information security officer (CISO) or the designated risk owner.'1

The CISO is the senior executive who is responsible for overseeing and managing the information security program of an organization. The CISO has the authority and expertise to assess the risks, determine the risk appetite and tolerance levels, and select the most suitable risk treatment options for each risk. The CISO also has the accountability and responsibility for implementing, monitoring, and reporting on the risk treatment activities.


Contribute your Thoughts:

0/2000 characters
Sharee
2 hours ago
I’ve seen similar questions where the CISO was the right answer, but I wonder if it’s different when it comes to low- and medium-level vulnerabilities.
upvoted 0 times
...
Marsha
5 days ago
I’m a bit confused about this one. The security manager seems like a logical choice, but I guess it depends on the organization's structure.
upvoted 0 times
...
Florencia
10 days ago
I remember a practice question where the CISO was involved in risk decisions, but I feel like the business owner has the final say.
upvoted 0 times
...
Terry
16 days ago
I think the business owner is usually the one who decides on risk treatment options, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel