Risk owner for the use of mobile devices
Assign topic to the user
Answer: This depends on the risk(s) you identified related to this activity. If there is a risk of loss of data or data leakage, the risk owner could be the Head of IT department; if there is a risk of inappropriate usage of the device, the risk owner could be the security officer, etc.
See also this article: Risk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Comment as guest or Sign in
Jan 16, 2019

