exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 598 discussion

Actual exam question from Isaca's CRISC
Question #: 598
Topic #: 1
[All CRISC Questions]

Who should be accountable for ensuring effective cybersecurity controls are established?

  • A. Security management function
  • B. Enterprise risk function
  • C. Risk owner
  • D. IT management
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mozzie22
11 months ago
C Risk Owner - the key word here is "Accountable"
upvoted 1 times
...
Staanlee
1 year, 4 months ago
Selected Answer: A
A. Security management function. The accountability for ensuring effective cybersecurity controls are established typically lies with the "A. Security management function." This function is responsible for overseeing the organization's cybersecurity strategy, policies, and controls. They ensure that appropriate security measures are in place to protect the organization's information assets from cyber threats. While the other options (enterprise risk function, risk owner, IT management) may play roles in the overall cybersecurity effort, the primary accountability for cybersecurity control establishment usually rests with the security management function.
upvoted 1 times
...
CbtL
1 year, 9 months ago
Selected Answer: C
Agree it is C. The question is about accountability, so the risk owner. The other options are more on the responsibility side of the equation.
upvoted 1 times
...
naifitno
1 year, 10 months ago
Selected Answer: A
The risk owner also has a responsibility to ensure effective cybersecurity controls are established, but this is typically only within the scope of their specific area of responsibility or risk. For example, a risk owner might be responsible for ensuring that a particular system or application is secure and that appropriate controls are in place to protect it. However, they may not have the authority or expertise to establish cybersecurity controls across the entire organization. The security management function, on the other hand, is responsible for the overall cybersecurity posture of the organization, including the development and implementation of controls that address risks across the enterprise. Therefore, while the risk owner has an important role to play in cybersecurity, they are not typically the primary party responsible for ensuring effective cybersecurity controls are established.
upvoted 1 times
Koulyo
1 year, 9 months ago
q is on accountability and not responsibility.
upvoted 1 times
...
...
john_boogieman
1 year, 10 months ago
Selected Answer: C
Agree.
upvoted 2 times
...
aki
1 year, 10 months ago
why not A?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...