Study. uk . com
  1. Home
  2. All questions
  3. Question 28

CISM study material · question 28 of 1000

Each system owner reports that risk to their own system is acceptable, yet the organisation wants to know whether risk is acceptable overall. Which role produces that view under SP 800-39?

  1. Each mission owner, summing their own systems
  2. The authorising official for the largest system, whose authorisation decision already covers the greatest share of exposure
  3. The risk executive function, which determines organisational risk from aggregated risk across all systems
  4. The internal audit function during its annual cycle, since its independent review is the only view spanning every system in the estate
Show the answer

Answer: C. The risk executive function, which determines organisational risk from aggregated risk across all systems

The risk executive function determines organisational risk based on the aggregated risk from operating and using all systems and their environments, a perspective no individual system owner holds.

Source: NIST SP 800-39 (NIST) — Sec. 2.3.2 Risk Executive (Function)

Challenge yourself on this topic → Study as cards