Assign topic to the user
Your assumptions are correct.
The best is for the risk owner to be the role more interested in treat the risk and with enough authority to do something about it, in this case, the Accounting Director of company X. As for the person to perform risk assessment, you should consider the person with the most knowledge about the accounting program and related processes (in general this person is known as the key user).
This article will provide you a further explanation about risk owners:
- Risk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Comment as guest or Sign in
Jul 23, 2021

