The most important attribute when assigning a risk owner is that the risk owner has the authority to take action on the risk (B). In CISM, risk ownership is fundamentally about accountability and decision-making authority. The risk owner must be empowered to decide on risk treatment options—such as mitigation, transfer, acceptance, or avoidance—and to allocate resources or approve changes necessary to address the risk.
While reassessing risk after remediation (A) and updating the risk register (C) are important responsibilities, they are administrative and follow-on activities that do not, by themselves, ensure effective risk management. Ownership of the failed control (D) is not required; in fact, CISM distinguishes between risk ownership (business accountability) and control ownership (operational responsibility). The risk owner is typically a business role accountable for the impact of the risk, not necessarily the individual responsible for implementing or operating the control.
CISM guidance consistently stresses that risk owners must have sufficient authority, accountability, and understanding of business impact to make informed decisions aligned with the organization’s risk appetite. Without authority, risk ownership becomes ineffective and purely symbolic.
[References:, ISACA CISM Review Manual, Information Risk Management — risk ownership, accountability, and risk response, ISACA CISM Exam Content Outline, Domain 1: Information Risk Management, , , , ]
Submit