Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 712-50 All Questions

View all questions & answers for the 712-50 exam

Exam 712-50 topic 1 question 255 discussion

Actual exam question from ECCouncil's 712-50
Question #: 255
Topic #: 1
[All 712-50 Questions]

Acceptable levels of information security risk tolerance in an organization should be determined by?

  • A. Corporate compliance committee
  • B. CEO and board of director
  • C. CISO with reference to the company goals
  • D. Corporate legal counsel
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
johndoe69
5 months, 3 weeks ago
Selected Answer: B
NIST Special Publication 800-39: This publication emphasizes that senior leaders, including the CEO and the board of directors, are responsible for determining the organization’s risk tolerance levels. They set the tone and direction for risk management, ensuring that it aligns with the organization's mission and business objectives (NIST, 2011). ISACA (Information Systems Audit and Control Association): ISACA states that the board of directors and executive management are ultimately responsible for determining the acceptable level of risk, as they have the comprehensive view of the organization's strategic objectives and risk appetite (ISACA, 2020). These references confirm that the CEO and the board of directors are best positioned to determine the acceptable levels of risk tolerance within an organization.
upvoted 1 times
...
Malik2165
2 years, 10 months ago
CISO determine the Risk, not the tolerance, hence given answer is correct
upvoted 1 times
...
Rufus1
3 years, 1 month ago
it should be C. The key word is "determined", and CISO is determining the cyber-risk tolerance, then proposing to Board for validation. Other opinions ?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...