QuestionQ69

Governance

An IT control gap has been identified in a key process. Who is the MOST appropriate owner of the risk associated with this gap?

  • A Business process owner
  • B Chief information security officer
  • C Operational risk manager
  • D Key control owner
Explanation

The business process owner is accountable for the process and has the authority to ensure that risks arising from control gaps are assessed and appropriately treated. Control, security, and operational-risk roles may support oversight and remediation, but they do not ordinarily own the underlying business-process risk.

Community Discussion

No comments yet. Be the first to start the discussion!