QuestionQ215

Risk Response and Reporting

A risk practitioner has determined that the organization’s secondary data center lacks redundancy for a critical application. Who should be authorized to accept the related risk?

  • A Business continuity director
  • B Business application owner
  • C Disaster recovery manager
  • D Data center manager
Explanation

Acceptance of a risk arising from insufficient redundancy for a critical application belongs to the business application owner, who is accountable for the application’s business requirements, impact, and risk tolerance. Continuity, disaster-recovery, and data-center managers support planning and operations but do not own the business decision to accept the application risk.

Community Discussion

No comments yet. Be the first to start the discussion!