QuestionQ551

Risk Response and Reporting

An organization’s internal auditors have identified a new IT control deficiency in the organization’s identity and access management (IAM) system. What is most important for the risk practitioner to do?

  • A perform a follow-up risk assessment to quantify the risk impact
  • B verify that applicable risk owners understand the risk
  • C implement compensating controls to address the deficiency
  • D recommend replacement of the deficient system
Explanation

Risk owners hold the authority and accountability to make risk-based decisions and own the loss associated with a realized risk scenario. They must therefore understand a newly identified IAM control deficiency before an appropriate response—such as further assessment, risk acceptance, mitigation, or compensating controls—can be selected. Risk practitioners facilitate this governance process but do not unilaterally implement the treatment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!