Option D every time with ISACA, gets me how often folks overthink this. If you don’t have risk ownership documented, nobody’s accountable and nothing gets managed in practice.
Q: 3
Which of the following is the MOST important detail to capture in an organization's risk register?
Options
Discussion
Ownership is the main thing that makes a risk register actionable, so D. If nobody's assigned, nothing gets done even if you know the severity. Seen similar in exam practice, pretty sure this is what ISACA expects but correct me if you disagree.
B tbh
D imo. You absolutely need risk ownership recorded so someone is on the hook for action and tracking. Without that, risks fall through the cracks. Severity matters too but accountability is what makes the register useful. Pretty sure ISACA exams focus on this.
Had something like this in a mock. The key thing is always risk ownership-D. Without an owner, risks just sit there. Ownership means someone’s actually responsible for mitigation and follow-up. Pretty sure this is what they want here, agree?
Be respectful. No spam.
Question 3 of 35