職務分離制御は、アクセスを評価する際にすべての適用可能な機能を考慮しなかったため、効果的ではないことが判明しました。制御がリスクに効果的に対処できるように設計されていることを確認する責任は誰にありますか?
正解:B
The control owner is the person who is responsible for ensuring that the control is designed to effectively address risk. The control owner is also responsible for implementing, operating, monitoring, and maintaining the control. The control owner should ensure that the control is aligned with the risk owner's risk appetite and tolerance, and that the control is periodically reviewed and updated to reflect changes in the risk environment.
The risk manager, the control tester, and the risk owner are not directly responsible for the design of the control, although they may provide input, feedback, or approval. References = Risk and Information Systems Control Study Manual, Chapter 1, Section 1.3.2, page 1-15.