CGEIT · Question #107
Which of the following is the MOST important reason for selecting IT key risk indicators (KRIs)?
The correct answer is A. Demonstrating the effectiveness of IT risk policies. The most important reason for selecting IT Key Risk Indicators (KRIs) is to demonstrate the effectiveness of IT risk policies and controls.
Question
Which of the following is the MOST important reason for selecting IT key risk indicators (KRIs)?
Options
- ADemonstrating the effectiveness of IT risk policies
- BAssessing the current IT controls model
- CEnabling comparison against similar IT KRIs
- DIncreasing the probability of achieving IT goals
How the community answered
(20 responses)- A80% (16)
- B5% (1)
- C10% (2)
- D5% (1)
Why each option
The most important reason for selecting IT Key Risk Indicators (KRIs) is to demonstrate the effectiveness of IT risk policies and controls.
KRIs serve as early warning signals, and by tracking them, an organization can gain insight into how well its IT risk policies and associated controls are performing. This allows for timely adjustments and provides measurable evidence of their efficacy in managing risk exposures, thereby demonstrating the actual performance of the risk management framework.
While KRIs can *inform* the assessment of IT controls by indicating potential control weaknesses, their primary purpose is broader: to indicate the *level of risk* and the effectiveness of risk policies themselves.
Enabling comparison against similar IT KRIs can be a useful *application* for benchmarking, but it is not the *most important reason* for selecting them in the first place.
KRIs help manage risks that *could hinder* the achievement of IT goals, thereby indirectly increasing the probability of achieving them, but their direct and most important function is to monitor the effectiveness of risk policies.
Concept tested: Purpose of Key Risk Indicators (KRIs)
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-management
Topics
Community Discussion
No community discussion yet for this question.