Who should be accountable for ensuring effective cybersecurity controls are established?
Correct Answer: B
According to the CRISC Review Manual (Digital Version), the security management function is responsible for ensuring that effective cybersecurity controls are established and maintained. The security management function should:
Define the cybersecurity strategy and objectives aligned with the enterprise's risk appetite and business goals Establish and maintain the cybersecurity policies, standards, procedures and guidelines Implement and monitor the cybersecurity controls and processes Coordinate and communicate with other stakeholders, such as risk owners, IT management, enterprise risk function, internal and external auditors, regulators and third parties Report on the cybersecurity performance and risk posture to senior management and the board Continuously improve the cybersecurity capabilities and maturity References = CRISC Review Manual (Digital Version), Chapter 1: IT Risk Identification, Section 1.4: IT Risk Management Roles and Responsibilities, pp. 29-301