Study. uk . com
  1. Home
  2. All questions
  3. Question 69

CISM study material · question 69 of 1000

IR 8286 distinguishes two risk officer roles. Which pairing correctly describes them?

  1. A cybersecurity risk officer manages the risk process for a system or set of systems; an enterprise risk officer is accountable for risk across the enterprise
  2. A cybersecurity risk officer owns the whole enterprise risk register; an enterprise risk officer owns every single one of the controls that were selected to treat all of the entries recorded in it
  3. A cybersecurity risk officer is an external assessor engaged for each review cycle; an enterprise risk officer is an internal appointment holding the standing accountability
  4. The two titles describe one role under different names, the enterprise title being adopted once the estate passes the size at which a single register stops being workable
Show the answer

Answer: A. A cybersecurity risk officer manages the risk process for a system or set of systems; an enterprise risk officer is accountable for risk across the enterprise

IR 8286 defines the cybersecurity risk officer as managing the risk process for a given system or systems, and the enterprise risk officer as the senior official accountable for managing and communicating risk across the enterprise.

Source: NIST IR 8286 (NIST) — Sec. 3.1.1 Notional Risk Management Roles

Challenge yourself on this topic → Study as cards