C. The business process owner of the exposed assets.
The risk tolerance of the business process owner of the exposed assets matters most when making a risk decision. This is because the business process owner is responsible for the day-to-day operations and outcomes of the processes and assets in question. They have the most intimate knowledge of the business context, objectives, and the potential impact of the risks on the organization's operations.
C. The business process owner of the exposed assets
When making a risk decision, the risk tolerance of the business process owner of the exposed assets matters most. Here's why:
Ownership and Accountability: The business process owner is responsible for the assets and operations related to the specific business process. They are directly accountable for the outcomes and risks associated with that process.
Contextual Understanding: The business process owner has a deep understanding of the specific business operations, objectives, and priorities. They can evaluate risks in the context of how they impact the achievement of business goals.
Risk-Benefit Trade-offs: Business process owners are in the best position to assess the trade-offs between risk and potential benefits. They can weigh the impact of risks against the potential advantages of pursuing a particular course of action.
Because the business process owner is responsible for the assets and the processes that use them. They understand the potential impact of a security breach on the business operations, and therefore have the most relevant information and insight on the acceptable level of risk. The business process owner's risk tolerance will impact the decisions they make regarding the allocation of resources to mitigate risk, as well as their willingness to accept certain risks in order to achieve business goals. The views and concerns of customers, information security managers, auditors, regulators, and standards organizations are important, but the business process owner's risk tolerance is the most relevant when making a risk decision.
I think D is correct because regulators and standards orgs have certain requirements. And Audit will be relying on the business tolerance, yes? I guess I see it.
This section is not available anymore. Please use the main Exam Page.CRISC Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
hussmohsin
Highly Voted 3 years, 2 months agoBeeSz
2 years, 10 months agoSuperMax
Most Recent 5 months, 1 week agoStaanlee
7 months, 2 weeks agoCbtL
1 year agojohn_boogieman
1 year, 2 months agoBoubou480
1 year, 2 months agoRaj1510
2 years, 2 months agoPunkMom
3 years, 6 months agotravdaman
3 years, 6 months agoRooks
3 years, 7 months ago