Study. uk . com
  1. Home
  2. All questions
  3. Question 27

CISM study material · question 27 of 1000

A manager reads that the organisation must establish a risk executive and assumes this means recruiting an individual into a new post. How should this be corrected under SP 800-39?

  1. It must be a single named individual reporting to the chief executive, since a committee cannot be held accountable for accepting risk on its own
  2. It must be an external party to preserve independence
  3. The risk executive is a function that may be filled by an individual, an office, or a group such as a risk board
  4. It is filled automatically by the chief information security officer
Show the answer

Answer: C. The risk executive is a function that may be filled by an individual, an office, or a group such as a risk board

SP 800-39 describes the risk executive as a function rather than a post. It can be filled by one individual or office with expert staff, or by a designated group such as a risk board or steering committee.

Source: NIST SP 800-39 (NIST) — Sec. 2.3.2 Risk Executive (Function)

Challenge yourself on this topic → Study as cards