QuestionQ282

Information Security Risk Management

An organization’s primary product is a customer-facing application provided through Software as a Service (SaaS). The lead security engineer has just discovered a major security vulnerability at the primary cloud provider. Who within the organization is PRIMARILY accountable for the related risk?

  • A The data owner
  • B The information security manager
  • C The security engineer
  • D The application owner
Explanation

The application owner is primarily accountable for risks to the customer-facing application and for ensuring that appropriate risk treatment or escalation occurs. A cloud provider’s underlying vulnerability does not transfer the organization’s responsibility for the business risk affecting its application. Security personnel identify and advise on the risk, while data owners are accountable for their data assets rather than overall application risk.

Community Discussion

No comments yet. Be the first to start the discussion!