組織のインターネットに接続されたサーバーが、最新のセキュリティ パッチが適用されていなかったために攻撃を受けました。不適切なパッチ管理に関連するリスクは、リスク レジスタに記録され、受け入れられていました。組織に関連する損失について、誰が責任を負うべきでしょうか。
正解:A
The risk owner is the person who should be accountable for any related losses to the organization, because they are the person who has the authority and responsibility to manage the risk and its associated controls.The risk owner is also the person who accepts the risk and its residual level, and who monitors and reports on the risk status and performance. The IT risk manager, the server administrator, and the risk practitioner are all involved in the riskmanagement process, but they are not the person who should be accountable for the risk and its outcomes, as they do not have the ultimate decision-making power and accountability for therisk.
References = Risk and Information Systems Control Study Manual, Chapter 3, Section 3.1.1, page 79