QuestionQ514

Governance

Which stakeholder is MOST important to involve in defining a risk profile while selecting a new third-party application?

  • A The information security manager
  • B The third-party risk manager
  • C The application vendor
  • D The business process owner
Explanation

The business process owner is responsible for the process requirements, design approval, and performance. That owner best identifies the application’s intended use, process criticality, data exposure, and business impact—the factors needed to establish an appropriate third-party risk profile. ISACA notes that vendor criticality can be assessed with business process owners using business, financial, and client impacts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!