Who decides to change a specific control?

Risk Management
Answer Correct answer: C — The control owner decides on changes to the specific control.

Who should decide whether a specific control should be changed once risk is approved for mitigation?

  1. Risk owner
  2. Data owner
  3. Control owner Correct Answer
  4. Process owner

Community Votes

C
50%
D
50%

50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between accountability for the risk (Risk Owner) and responsibility for the control mechanism (Control Owner), often confusing candidates who conflate process ownership with control modification.

Once a risk is approved for mitigation, the control owner is responsible for deciding on specific control changes to ensure effectiveness, distinguishing this role from the risk owner who accepts the risk.

Choosing the Risk Owner (A) is a common error because they approve the mitigation strategy, but they do not manage the operational details of the control itself.

Community Discussion (3 comments)

SHERLOCKAWS 👍 1 Selected: C
I consider as better suited is C. Control owner. The control owner is the person responsible for the implementation, and ongoing operation of a specific control. Regarding D. Process owner. yes they’re responsible for business processes. If a control impacts their process, they might be involved, but changing the control is still up to the control owner.
Josef4CISM 👍 1 Selected: D
I feel like the "suggested correct" answer options of the very last questions of this question pool are not very good. The process owner should decide whether to change controls as he is accountable to security
Booict 👍 2
C-he control owner oversees the implementation, monitoring, and adjustment of controls to address identified risks. They ensure that controls remain effective and aligned with risk management objectives

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Control Owner is responsible for the implementation, maintenance, and ongoing effectiveness of a specific control. When a risk is approved for mitigation, the Control Owner determines the necessary adjustments to the control to address that risk, ensuring it operates as intended. This aligns with ISACA's separation of duties where operational control lies with the Control Owner.

Why the Other Options Are Wrong

The Risk Owner (A) is accountable for the risk and decides to accept or mitigate it, but not the technical changes to the control. The Data Owner (B) is responsible for data classification and custodianship. The Process Owner (D) manages business processes and while impacted by controls, does not own the security control mechanism itself.

Community Comment Notes

Comment [1] correctly identifies the Control Owner's oversight of implementation and adjustment. Comment [2] reinforces this by distinguishing the Control Owner's technical responsibility from the Process Owner's business focus, noting that the Process Owner might be involved but doesn't make the final decision on the control change.

Exam Strategy

Focus on the specific lifecycle of the control; the person who 'owns' the mechanism (Control Owner) is the one who modifies it, whereas the person who 'owns' the risk (Risk Owner) only approves the treatment strategy.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide