In theThree Lines Model, thefirst line(operational management) owns and manages risk through daily operations.
Per ISACA:
“Operational management, as the first line of defense, is responsible for maintaining effective internal controls and executing risk management processes.”
Oversight is the second line’s role; audits belong to the third line.
Hence,Ais correct.
CRISC Reference:Domain 1 – IT Risk Governance, Topic: Three Lines of Defense Model.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit