nerdexam
Isaca

CGEIT · Question #11

A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is…

The correct answer is A. understand the enterprise's risk tolerance. To establish appropriate risk policies for IT, especially concerning mobile applications, a CTO must first understand the enterprise's overall risk tolerance.

Submitted by brentm· Apr 18, 2026Risk Optimization

Question

A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:

Options

  • Aunderstand the enterprise's risk tolerance.
  • Bcreate an IT risk scorecard.
  • Cmap the business goals to IT risk processes.
  • Didentify the mobile technical requirements.

How the community answered

(31 responses)
  • A
    74% (23)
  • B
    6% (2)
  • C
    16% (5)
  • D
    3% (1)

Why each option

To establish appropriate risk policies for IT, especially concerning mobile applications, a CTO must first understand the enterprise's overall risk tolerance.

Aunderstand the enterprise's risk tolerance.Correct

The enterprise's risk tolerance defines the acceptable deviation from the risk appetite and dictates the maximum level of risk the organization is willing to bear. Understanding this threshold is crucial for the CTO to develop risk policies for mobile applications that are aligned with the organization's overarching comfort level for potential threats and vulnerabilities, ensuring policies are neither excessively restrictive nor overly permissive.

Bcreate an IT risk scorecard.

Creating an IT risk scorecard is a tool for monitoring and reporting risk, which comes after defining the risk policies and acceptable levels.

Cmap the business goals to IT risk processes.

Mapping business goals to IT risk processes is part of aligning risk management with strategy, but understanding the fundamental acceptable risk level (tolerance) precedes policy creation.

Didentify the mobile technical requirements.

Identifying mobile technical requirements is a detailed technical step for implementation or security controls, not the initial strategic step for creating risk policies.

Concept tested: Risk policy development basis

Topics

#Risk Management#Risk Tolerance#IT Governance#Policy Development

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice