Who should be accountable for ensuring effective cybersecurity controls are established?
Correct Answer: B
According to the CRISC Review Manual (Digital Version), the security management function is responsible for ensuring that effective cybersecurity controls are established and maintained. The security management function should:
* Define the cybersecurity strategy and objectives aligned with the enterprise's risk appetite and business goals
* Establish and maintain the cybersecurity policies, standards, procedures and guidelines
* Implement and monitor the cybersecurity controls and processes
* Coordinate and communicate with other stakeholders, such as risk owners, IT management, enterprise risk function, internal and external auditors, regulators and third parties
* Report on the cybersecurity performance and risk posture to senior management and the board
* Continuously improve the cybersecurity capabilities and maturity
References = CRISC Review Manual (Digital Version), Chapter 1: IT Risk Identification, Section 1.4: IT Risk Management Roles and Responsibilities, pp. 29-301