answersLogoWhite

0


Best Answer

The ultimate responsibility for organizational risk in terms of computer resources usually falls to the Chief Information Officer, Chief Technology Officer - or the equivalent. In large organizations the responsibility is usually delegated to someone specifically responsible for computer security while the CIO or CTO assumes overall responsibility of acquisition, maintenance, policies, procedures, etc. for all IT assets. As an example, in DODD 8500.2, the US Department of Defense appoints Designated Approving Authorities (DAAs) who formally accept responsibility for the risks for operating all systems under their purview. Although the CIO or CTO is officially responsible for organizational risk, the rest of the leadership of an organization can sometimes be held legally responsible for failures of security and risk exposure if they can be shown to be culpable by way of failing to create and enforce policies and procedures to manage risk or failing to provide adequate funding to permit the CIO to do so.

User Avatar

Wiki User

12y ago
This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: Who is ultimately responsible for organizational risk?
Write your answer...
Submit
Still have questions?
magnify glass
imp