Who owns risk of unauthorized application data access?
Of the following, who should own the risk associated with unauthorized access to application data?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between accountability (ownership) and execution (custodians/admins), often trapping those who confuse technical implementation with ultimate responsibility.
The application owner is accountable for the risk of unauthorized access to application data, as they define business requirements and sensitivity. Community consensus confirms this responsibility aligns with their oversight of the application's security posture.
Choosing Data custodian (A) is a common error because custodians implement security controls, but they do not own the business risk or define access requirements.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The application owner is accountable for the business process supported by the application. They are best positioned to understand the data's sensitivity and the impact of unauthorized access, making them the rightful owner of the risk. ISACA principles consistently assign risk ownership to the role with decision-making authority over the asset.Why the Other Options Are Wrong
Data custodians implement technical controls but lack business authority. Application developers build the software but do not manage operational access or business risk. Access administrators configure permissions based on requirements provided by others, rather than owning the risk itself.Community Comment Notes
Comments unanimously support option C, noting that the title implies responsibility. One user highlights that the owner understands business context and sensitivity, which is crucial for proper risk management.Exam Strategy
Remember the RACI model distinctions for CISM: owners are accountable (risk), while custodians and admins are responsible for execution. Focus on who defines the 'why' and 'what' versus the 'how'.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →