Who decides to change a specific control?
Who should decide whether a specific control should be changed once risk is approved for mitigation?
Community Votes
50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between accountability for the risk (Risk Owner) and responsibility for the control mechanism (Control Owner), often confusing candidates who conflate process ownership with control modification.
Once a risk is approved for mitigation, the control owner is responsible for deciding on specific control changes to ensure effectiveness, distinguishing this role from the risk owner who accepts the risk.
Choosing the Risk Owner (A) is a common error because they approve the mitigation strategy, but they do not manage the operational details of the control itself.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Control Owner is responsible for the implementation, maintenance, and ongoing effectiveness of a specific control. When a risk is approved for mitigation, the Control Owner determines the necessary adjustments to the control to address that risk, ensuring it operates as intended. This aligns with ISACA's separation of duties where operational control lies with the Control Owner.Why the Other Options Are Wrong
The Risk Owner (A) is accountable for the risk and decides to accept or mitigate it, but not the technical changes to the control. The Data Owner (B) is responsible for data classification and custodianship. The Process Owner (D) manages business processes and while impacted by controls, does not own the security control mechanism itself.Community Comment Notes
Comment [1] correctly identifies the Control Owner's oversight of implementation and adjustment. Comment [2] reinforces this by distinguishing the Control Owner's technical responsibility from the Process Owner's business focus, noting that the Process Owner might be involved but doesn't make the final decision on the control change.Exam Strategy
Focus on the specific lifecycle of the control; the person who 'owns' the mechanism (Control Owner) is the one who modifies it, whereas the person who 'owns' the risk (Risk Owner) only approves the treatment strategy.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →