CGEIT · Question #134
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing…
The correct answer is C. key risk indicators (KRIs). To provide ongoing assurance that significant IT risk is proactively monitored and within tolerance, the best approach is to develop Key Risk Indicators (KRIs).
Question
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
Options
- Aan IT risk appetite statement.
- Ba risk management policy.
- Ckey risk indicators (KRIs).
- Da risk register.
How the community answered
(38 responses)- A11% (4)
- B3% (1)
- C82% (31)
- D5% (2)
Why each option
To provide ongoing assurance that significant IT risk is proactively monitored and within tolerance, the best approach is to develop Key Risk Indicators (KRIs).
An IT risk appetite statement defines the level of risk an organization is willing to accept but does not provide ongoing monitoring or assurance of current risk levels.
A risk management policy establishes the rules and procedures for managing risk but does not offer direct, continuous monitoring of actual risk levels.
Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposure in a specific area, enabling proactive monitoring and management to ensure risks do not exceed agreed tolerance levels.
A risk register is a list of identified risks, their assessments, and mitigation plans, but it is a static record and does not inherently provide proactive, real-time monitoring of risk levels and tolerance adherence.
Concept tested: Proactive IT risk monitoring
Source: https://www.isaca.org/resources/isaca-journal/issues/2020/volume-5/kr-you-serious
Topics
Community Discussion
No community discussion yet for this question.