712-50 Exam QuestionsBrowse all questions from this exam

712-50 Exam - Question 89


Acceptable levels of information security risk tolerance in an organization should be determined by?

Show Answer
Correct Answer: B

Determining acceptable levels of information security risk tolerance in an organization is a strategic decision that aligns with the organization’s mission and business objectives. Therefore, it falls under the responsibility of the CEO and the board of directors. These individuals have a comprehensive view of the organization's strategic goals and risk appetite, making them best positioned to establish risk tolerance levels.

Discussion

3 comments
Sign in to comment
Rufus1Option: C
Oct 20, 2021

it should be C. The key word is "determined", and CISO is determining the cyber-risk tolerance, then proposing to Board for validation. Other opinions ?

Malik2165Option: C
Jan 8, 2022

CISO determine the Risk, not the tolerance, hence given answer is correct

johndoe69Option: B
Jun 3, 2024

NIST Special Publication 800-39: This publication emphasizes that senior leaders, including the CEO and the board of directors, are responsible for determining the organization’s risk tolerance levels. They set the tone and direction for risk management, ensuring that it aligns with the organization's mission and business objectives (NIST, 2011). ISACA (Information Systems Audit and Control Association): ISACA states that the board of directors and executive management are ultimately responsible for determining the acceptable level of risk, as they have the comprehensive view of the organization's strategic objectives and risk appetite (ISACA, 2020). These references confirm that the CEO and the board of directors are best positioned to determine the acceptable levels of risk tolerance within an organization.