CGEIT · Question #11
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is…
The correct answer is A. understand the enterprise's risk tolerance. To establish appropriate risk policies for IT, especially concerning mobile applications, a CTO must first understand the enterprise's overall risk tolerance.
Question
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:
Options
- Aunderstand the enterprise's risk tolerance.
- Bcreate an IT risk scorecard.
- Cmap the business goals to IT risk processes.
- Didentify the mobile technical requirements.
How the community answered
(31 responses)- A74% (23)
- B6% (2)
- C16% (5)
- D3% (1)
Why each option
To establish appropriate risk policies for IT, especially concerning mobile applications, a CTO must first understand the enterprise's overall risk tolerance.
The enterprise's risk tolerance defines the acceptable deviation from the risk appetite and dictates the maximum level of risk the organization is willing to bear. Understanding this threshold is crucial for the CTO to develop risk policies for mobile applications that are aligned with the organization's overarching comfort level for potential threats and vulnerabilities, ensuring policies are neither excessively restrictive nor overly permissive.
Creating an IT risk scorecard is a tool for monitoring and reporting risk, which comes after defining the risk policies and acceptable levels.
Mapping business goals to IT risk processes is part of aligning risk management with strategy, but understanding the fundamental acceptable risk level (tolerance) precedes policy creation.
Identifying mobile technical requirements is a detailed technical step for implementation or security controls, not the initial strategic step for creating risk policies.
Concept tested: Risk policy development basis
Topics
Community Discussion
No community discussion yet for this question.