ISACA Exam Questions

Which of the following role carriers is accounted for analyzing risks, maintaining risk profile, and

Which of the following role carriers is accounted for analyzing risks, maintaining risk profile, and

risk-aware decisions?

A.
Business management

B.
Business process owner

C.
Chief information officer (CIO)

D.
Chief risk officer (CRO)

Explanation:

Business management is the business individuals with roles relating to managing a program. They
are typically accountable for analyzing risks, maintaining risk profile, and risk-aware decisions.
Other than this, they are also responsible for managing risks, react to events, etc.
Answer C is incorrect. CIO is the most senior official of the enterprise who is accountable for IT
advocacy; aligning IT and business strategies; and planning, resourcing and managing the
delivery of IT services and information and the deployment of associated human resources. CIO
has some responsibility analyzing risks, maintaining risk profile, and risk-aware decisions but is
not accounted for them.
Answer B is incorrect. Business process owner is an individual responsible for identifying process
requirements, approving process design and managing process performance. He/she is
responsible for analyzing risks, maintaining risk profile, and risk-aware decisions but is not
accounted for them.
Answer D is incorrect. CRO is the individual who oversees all aspects of risk management across
the enterprise. He/she is responsible for analyzing risks, maintaining risk profile, and risk-aware
decisions but is not accounted for them.