02. Risk and Control Ownership Flashcards

1
Q

Risk and Control Ownership

Owners are formally assigned and recorded to all…

A
  1. Risks
  2. Controls
  3. Assets
  4. Processes
  5. Procedures
  6. Records

187

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk and Control Ownership

Risk ownership may be assigned to one or several different managers psanning multiple functional areas because…

A

risks are likely to affect multiple (functional) areas of the business

187

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk and Control Ownership

The risk owner is not necessarilly the person accountbale for mkaing the risk treatment decision or owner of the asset but generally is the…

A

department or business unit owner within which the risk resides

187

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk and Control Ownership

This person should have a say in the risk treatment decision with regard to whether they (the individual) are inclined to accept the risk or whether they want the risk reduced through mitigation

A

Risk owner

187

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk and Control Ownership

Risk managers or security managers should routinely monitor risks and if there are any changes, they should inform the…

A

Risk owner to help them remain fully informed and to continue to own the risk effectively

187

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk and Control Ownership

When an individual leaves a business or changes role, risk ownership should remain with the position and assigned to the replacement individual. If the position is not filled, ownership should be..

A

Transferred to the next higher-up in the organisation

188

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Risk and Control Ownership

To ensure that controls become and remain effective, management should formally…

A

assign responsibility and ownership of each control

188

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk and Control Ownership

Authority to make decisions about the operation of controls should be with…

A

The Control Owner

188

How well did you know this?
1
Not at all
2
3
4
5
Perfectly