NIST Special Publication 800-39: This publication emphasizes that senior leaders, including the CEO and the board of directors, are responsible for determining the organization’s risk tolerance levels. They set the tone and direction for risk management, ensuring that it aligns with the organization's mission and business objectives (NIST, 2011).
ISACA (Information Systems Audit and Control Association): ISACA states that the board of directors and executive management are ultimately responsible for determining the acceptable level of risk, as they have the comprehensive view of the organization's strategic objectives and risk appetite (ISACA, 2020).
These references confirm that the CEO and the board of directors are best positioned to determine the acceptable levels of risk tolerance within an organization.
it should be C.
The key word is "determined", and CISO is determining the cyber-risk tolerance, then proposing to Board for validation. Other opinions ?
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
johndoe69
5 months, 3 weeks agoMalik2165
2 years, 10 months agoRufus1
3 years, 1 month ago