Valid CRISC Dumps shared by EduDump.com for Helping Passing CRISC Exam! EduDump.com now offer the newest CRISC exam dumps, the EduDump.com CRISC exam questions have been updated and answers have been corrected get the newest EduDump.com CRISC dumps with Test Engine here:
An organization uses an automated vulnerability scanner to identify potential vulnerabilities on various enterprise systems. Who is accountable for ensuring the vulnerabilities are mitigated?
Correct Answer: D
System owners hold ultimate accountability for managing risks associated with their systems, including vulnerability mitigation. ISACA CRISC defines: "The system owner is responsible for ensuring that security controls are implemented and that vulnerabilities identified in their systems are addressed." System administrators perform mitigation activities, but accountability (oversight and confirmation) remains with the system owner. * A: Data owners focus on data classification. * B: InfoSec managers oversee policy, not execution. * C: Admins implement controls but don't own the risk. D is correct because ownership equates to accountability. CRISC Reference: Domain 1 - IT Risk Governance, Topic: Roles and Responsibilities in Risk Management.