ある大規模組織がエンタープライズ リソース プランニング (ERP) システムを置き換えるにあたり、新しいシステムの給与モジュールを導入しないことを決定しました。代わりに、現在の給与システムを引き続き使用します。ERP と給与システムが期待どおりに動作しなくなった場合、次の誰がリスクを負うべきでしょうか。
正解:A
The business owner should own the risk if the ERP and payroll system fail to operate as expected, because the business owner is ultimately responsible for the business processes and objectives that depend on the systems.
The other options are not the risk owners, because:
Option B: The ERP administrator is responsible for the technical aspects of the ERP system, but not the payroll system or the business outcomes.
Option C: The project steering committee is responsible for overseeing the project of replacing the ERP system, but not the ongoing operation and maintenance of the systems or the business risks.
Option D: The IT project manager is responsible for managing the project of replacing the ERP system, but not the payroll system or the business risks. References = Risk and Information Systems Control Study Manual, 7th Edition, ISACA, 2020, p. 90.