Who is BEST suited to provide information to the risk practitioner about the effectiveness of a technical control associated with an application?
Correct Answer: A
Role of the System Owner:
* The system owner is responsible for the overall operation and management of an application or system.
This includes ensuring that technical controls are implemented and functioning as intended.
* They have detailed knowledge of the system's architecture, the controls in place, and how those controls are applied within the system.
Effectiveness of Technical Controls:
* Assessing the effectiveness of a technical control requires understanding its implementation, configuration, and operational context.
* The system owner is best positioned to provide this information as they manage and oversee the technical environment of the application.
Comparing Other Roles:
* Internal Auditor: While auditors review and evaluate the effectiveness of controls, they do so from an independent standpoint and might not have detailed, day-to-day operational insights.
* Process Owner: The process owner focuses on business processes rather than technical controls specific to an application.
* Risk Owner: The risk owner is responsible for managing risk but may not have the technical expertise or detailed operational knowledge of the system.
Supporting Information:
* According to the CRISC Review Manual, the system owner is often involved in the assessment and reporting of control effectiveness, especially regarding technical controls (CRISC Review Manual,
* Chapter 3: Risk Response and Mitigation, Section 3.1.3 Assessing Control Effectiveness) .