Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 762 discussion

Actual exam question from Isaca's CISM
Question #: 762
Topic #: 1
[All CISM Questions]

An organization's main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated risk?

  • A. The data owner
  • B. The information security manager
  • C. The security engineer
  • D. The application owner
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mad68
Highly Voted 1 year, 6 months ago
Selected Answer: D
D. The application owner. The application owner is responsible for overseeing the development, maintenance, and security of the customer-facing application. As the primary owner of the application, they have a direct stake in ensuring its security and mitigating any risks associated with it. The application owner is accountable for identifying and addressing vulnerabilities in the application, including those arising from the cloud provider's infrastructure or services. They must work closely with the security engineer and the information security manager to assess and manage the risk effectively. The application owner has the authority and responsibility to make decisions and take action to address the security vulnerability and protect the organization's customers and their data.
upvoted 6 times
Thavee
7 months ago
no, not application owner. The application is SaaS which is provided and own by provider not person within the organization. In fact, the answer should be the business process/operation owner, but the term was not there. The best answer is A. The data owner.
upvoted 1 times
...
...
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: B
The information security manager is primarily accountable for the associated risk in this scenario. The information security manager is responsible for overseeing the overall security posture of the organization, including identifying and mitigating risks to the organization's information and systems. In this case, the security vulnerability at the primary cloud provider poses a significant risk to the organization's customer-facing application and the information security manager would be responsible for managing and mitigating that risk.
upvoted 5 times
karanvp
1 year, 4 months ago
Application Owner or Data Owner must have accountable for Risks. IS Manager wont take any responsibility for any risk/incident. Owner means always responsible/accountable
upvoted 2 times
...
...
Booict
Most Recent 3 months, 1 week ago
Selected Answer: B
B - Reason being the Primary accountability for security risks related to the CLOUD PROVIDER may not fall squarely on Application Owner's shoulders. But if the question is vulnerability to the application, the ultimate accountability should be under the Application Owner.
upvoted 1 times
...
03allen
4 months, 2 weeks ago
Selected Answer: D
why ISM take responsibility for a non-security product...
upvoted 2 times
...
Thavee
7 months ago
Selected Answer: A
The application is SaaS which is provided and own by provider not person within the organization. In fact, the answer should be the "business process/operation owner", but the term was not there. The best answer is A. The data owner.
upvoted 1 times
...
heathsem
7 months, 4 weeks ago
Selected Answer: A
A. Data Owner
upvoted 1 times
...
yottabyte
8 months ago
Selected Answer: D
The application owner.
upvoted 1 times
...
sm24
9 months, 1 week ago
The question has keywords of "Within the organization" and "SaaS". Not sure if there will be an application owner in this scenario inside the organization. It would be the data owner.
upvoted 1 times
...
POWNED
9 months, 4 weeks ago
Selected Answer: B
Board of Directors/CEO are always the accountable party no matter what. Since board of Directors or CEO is not an option for an answer the second-best answer is the information security manager. If the company was sued do to a security incident it would land on the board of directors, but you better bet that the ISM would be fired because it is his priority to relay security posture to the BOD.
upvoted 1 times
...
Soleandheel
12 months ago
D. The application owner
upvoted 1 times
...
Marcovic00
12 months ago
Selected Answer: B
sec manager is accountable for the risk of course the app owner doesnt understand security to be accountable for it, he is just accountable for the app itslef so the manager will have to inform him
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: B
The information security manager is primarily responsible for overseeing the organization's overall security posture, which includes assessing and managing risks related to third-party services, such as the SaaS application delivered by the primary cloud provider. The application owner is responsible for the security and performance of the specific application in question. They should collaborate with the information security manager to address and mitigate risks related to the application's deployment in the cloud.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: A
The CISM Review Manual 15th Edition says: "Data owners, also known as information owners or business owners, are management personnel who are formally recognized to own specific business processes and the information used and created by those processes... Owners have management and oversight responsibilities to ensure appropriate controls are employed." (p. 22).
upvoted 4 times
...
wickhaarry
1 year, 3 months ago
Can anybody explain why application owner and not Data Owner ?
upvoted 1 times
...
richck102
1 year, 4 months ago
D. The application owner
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: D
he application owner is responsible for the overall management and performance of the customer-facing application. They have the primary accountability for ensuring the security, availability, and functionality of the application. Therefore, when a major security vulnerability is identified at the primary cloud provider, it directly impacts the application and its operations. The application owner would be responsible for assessing the risk, coordinating with the security engineer, and taking appropriate actions to address and mitigate the vulnerability.
upvoted 1 times
...
Gr3yGh0sT
1 year, 6 months ago
Man, I am on the fence on this one, but I am leaning towards D. The application owner is responsible for the overall security of the application, including the risks associated with the use of third-party cloud providers. The application owner should have a plan in place to mitigate the risks associated with the use of third-party cloud providers. This plan should include measures to identify and assess the risks, as well as measures to respond to incidents that occur.
upvoted 4 times
DERCHEF2009
1 year, 6 months ago
Agree with you
upvoted 1 times
...
Marcelus1714
9 months, 1 week ago
But it says "accountable". Agree with you that App Owner is responsible for all you said. But the management is the final accountable, and the only part of the management in the answers is sec manager. I also went for D, but not sure now.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...