Who owns risk of unauthorized application data access?

Information Risk Management
Answer Correct answer: C — Application owner accepts accountability for unauthorized access risks.

Of the following, who should own the risk associated with unauthorized access to application data?

  1. Data custodian
  2. Application developer
  3. Application owner Correct Answer
  4. Access administrator

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between accountability (ownership) and execution (custodians/admins), often trapping those who confuse technical implementation with ultimate responsibility.

The application owner is accountable for the risk of unauthorized access to application data, as they define business requirements and sensitivity. Community consensus confirms this responsibility aligns with their oversight of the application's security posture.

Choosing Data custodian (A) is a common error because custodians implement security controls, but they do not own the business risk or define access requirements.

Community Discussion (3 comments)

ServerBrain 👍 1 Selected: C
C. Application owner
fac161f 👍 1
Its in the name
Booict 👍 1
C - The application owner is responsible for the overall management, security, and performance of the application. They understand the business context, data sensitivity, and access requirements. Owning the risk ensures proper controls, monitoring, and mitigation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The application owner is accountable for the business process supported by the application. They are best positioned to understand the data's sensitivity and the impact of unauthorized access, making them the rightful owner of the risk. ISACA principles consistently assign risk ownership to the role with decision-making authority over the asset.

Why the Other Options Are Wrong

Data custodians implement technical controls but lack business authority. Application developers build the software but do not manage operational access or business risk. Access administrators configure permissions based on requirements provided by others, rather than owning the risk itself.

Community Comment Notes

Comments unanimously support option C, noting that the title implies responsibility. One user highlights that the owner understands business context and sensitivity, which is crucial for proper risk management.

Exam Strategy

Remember the RACI model distinctions for CISM: owners are accountable (risk), while custodians and admins are responsible for execution. Focus on who defines the 'why' and 'what' versus the 'how'.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide