A newly hired Chief Information Security Officer is establishing a governance structure and wants to define who is accountable for accepting residual risk that exceeds the organization's stated risk appetite. According to common governance practice, which role holds that accountability?
Accountability for risk that exceeds the approved appetite rests with the board or a committee it empowers, since governance ultimately owns organizational risk. Executives and security staff implement and monitor controls, but accepting risk beyond the tolerance level requires the governing body's authority and oversight.
Why this answer
Governance accountability for accepting risk beyond the approved appetite belongs to the board of directors or a delegated executive risk committee. Operational and assurance roles support risk management but do not own the decision to retain risk at the enterprise level.
Exam trap
The trap here is assuming that whoever manages security operations day to day also owns the authority to accept risk that exceeds the organization's appetite.