CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
During a risk assessment, a risk manager records a specific risk, its likelihood, and its potential impact, but leaves the 'risk owner' field unassigned. Why is assigning a risk owner important to the risk management process?
- AIt determines the annualized rate of occurrence for the risk
- BIt calculates the single loss expectancy for the risk
- CIt identifies who is accountable for monitoring and responding to the risk
- DIt sets the organization's overall risk appetite
Show answer & explanationAnswer & explanation
Correct answer: C. It identifies who is accountable for monitoring and responding to the risk
A risk owner is the individual or role accountable for managing a specific risk, including monitoring its status and ensuring the chosen response strategy is implemented. Without an assigned owner, risks may go unmanaged despite being documented.
Why the other options are wrong
- A. ARO is a statistical estimate of frequency, unrelated to ownership assignment.
- B. SLE is a calculated dollar value, not related to who owns the risk.
- D. Risk appetite is set by senior leadership/board, not determined by risk ownership.
Risk Owner
The individual or role formally accountable for managing a specific identified risk, including monitoring it and executing its response strategy.
- Typically documented in the risk register alongside likelihood and impact
- Ensures accountability so risks don't go unmanaged
- Different from risk appetite, which is set at the organizational level
Memory trick: No owner, no action — every risk needs a name attached.