
Certified Information Security Manager
Domain 2Objective 5
Risk and Control Ownership CISM Practice Questions (Page 5)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
24questions here
5free pages
6concepts
20%of the exam
Questions 21–24
- 21
A risk owner has delegated the responsibility for implementing a risk mitigation plan to a control owner. The control owner implements the plan, but the risk is not reduced to the expected level. The risk owner is held accountable by the board for the failure. Which statement best describes the accountability in this situation?
Select an answer first - 22
A large enterprise is restructuring its business units. As part of the restructuring, a risk owner for a critical operational risk is being moved to a new role. The risk is still relevant to the original business unit. What should the organization do to ensure the risk remains properly managed?
Select an answer first - 23
A financial services firm is implementing a new risk management framework. The CISO needs to assign ownership for a newly identified risk related to third-party data processing. Which individual is the most appropriate risk owner for this risk?
Select an answer first - 24
What is the primary purpose of risk and control owners communicating risk status to stakeholders?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.