Acceptable levels of information security risk tolerance in an organization should be determined by?
Acceptable levels of information security risk tolerance in an organization should be determined by?
Determining acceptable levels of information security risk tolerance in an organization is a strategic decision that aligns with the organization’s mission and business objectives. Therefore, it falls under the responsibility of the CEO and the board of directors. These individuals have a comprehensive view of the organization's strategic goals and risk appetite, making them best positioned to establish risk tolerance levels.
it should be C. The key word is "determined", and CISO is determining the cyber-risk tolerance, then proposing to Board for validation. Other opinions ?
CISO determine the Risk, not the tolerance, hence given answer is correct
NIST Special Publication 800-39: This publication emphasizes that senior leaders, including the CEO and the board of directors, are responsible for determining the organization’s risk tolerance levels. They set the tone and direction for risk management, ensuring that it aligns with the organization's mission and business objectives (NIST, 2011). ISACA (Information Systems Audit and Control Association): ISACA states that the board of directors and executive management are ultimately responsible for determining the acceptable level of risk, as they have the comprehensive view of the organization's strategic objectives and risk appetite (ISACA, 2020). These references confirm that the CEO and the board of directors are best positioned to determine the acceptable levels of risk tolerance within an organization.