CISM - Information Security Risk Management - Section 2.5

Establish risk and control ownership to ensure accountability for residual risk.

Establish clear risk ownership and control ownership to ensure that accountability for residual risk is assigned to an individual with the authority to act on it. Distinguish between the risk owner, who accepts residual risk, and the control owner, who is responsible for the control's design and operation.

Risk ownershipControl ownershipAccountabilityResidual risk

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

An organisation distinguishes between the owner of a risk and the owner of the controls that mitigate it. A new committee member asks what the control owner is primarily accountable for, as distinct from the risk owner. Which statement best describes the control owner's accountability?

  • AEnsuring the assigned mitigating controls remain designed and operating effectively so the risk stays at its intended level Correct
  • BDeciding whether the residual risk that remains after treatment falls within the organisation's approved risk appetite
  • CDetermining the inherent risk rating before any controls are applied to the affected business process
  • DSetting the organisation's overall risk appetite and tolerance thresholds that govern how much residual risk is acceptable
The control owner is accountable for keeping assigned controls effective over time, while the risk owner accepts and directs the residual risk. Separating the two roles ensures that someone is continuously responsible for the controls that hold a risk at its planned level, distinct from the risk owner who decides whether that residual level is acceptable.

Why A is correct: Correct because the control owner is accountable for the ongoing design and operating effectiveness of the specific controls that hold the risk at its planned residual level.

Why B is wrong: Tempting because it is a core ownership duty, but accepting residual risk against appetite is the risk owner's accountability, not the control owner's.

Why C is wrong: Tempting because rating sounds like an ownership task, but assessing inherent risk is part of the risk assessment process, not the control owner's standing accountability.

Why D is wrong: Tempting because it concerns risk levels, but appetite and tolerance are set by the board and senior management, far above the control owner's remit.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.