- Home
- All questions
- Question 69
CISM study material · question 69 of 1000
IR 8286 distinguishes two risk officer roles. Which pairing correctly describes them?
Show the answer
Answer: A. A cybersecurity risk officer manages the risk process for a system or set of systems; an enterprise risk officer is accountable for risk across the enterprise
IR 8286 defines the cybersecurity risk officer as managing the risk process for a given system or systems, and the enterprise risk officer as the senior official accountable for managing and communicating risk across the enterprise.
Source: NIST IR 8286 (NIST) — Sec. 3.1.1 Notional Risk Management Roles