リスク担当者は、組織のクラウド プロバイダーでのデータ損失に関連するリスク シナリオが、リスク シナリオを再割り当てする必要があるプロバイダーに割り当てられていることに気付きます。
正解:D
The risk scenario associated with data loss at the organization's cloud provider should be reassigned to the data owner, as they have the authority and responsibility to define the classification, retention, and disposal requirements for the data they own, and to manage the risk and controls related to the data. The risk scenario should not be assigned to the cloud provider, as they are an external party that may not have the same interest or accountability as the organization. Senior management, chief risk officer (CRO), and vendor manager are not the best choices, as they have different roles and responsibilities related to risk governance, strategy, or oversight, respectively, but they do not own the data. References = CRISC Review Manual, 7th Edition, page
154.