nerdexam
Isaca

CGEIT · Question #245

An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but…

The correct answer is B. Risk register. To make the best decision for customers when facing time-to-market pressure with unresolved security issues involving sensitive data, the CIO should review the risk register. This document provides a clear overview of identified security risks, their potential impacts, and…

Submitted by femi9· Apr 18, 2026Risk Optimization

Question

An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?

Options

  • AAcceptable use policy
  • BRisk register
  • CEthics standards
  • DChange ma agement policy

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    57% (17)
  • C
    27% (8)
  • D
    7% (2)

Why each option

To make the best decision for customers when facing time-to-market pressure with unresolved security issues involving sensitive data, the CIO should review the risk register. This document provides a clear overview of identified security risks, their potential impacts, and proposed mitigation strategies, enabling an informed risk-based decision.

AAcceptable use policy

An acceptable use policy defines how users can utilize IT resources, which is not directly relevant to addressing unmitigated security scan results on a new service.

BRisk registerCorrect

Reviewing the risk register will enable the CIO to make the best decision because it centralizes all identified security vulnerabilities, their potential impacts on sensitive personal data, likelihoods, and existing mitigation plans. This allows the CIO to understand the actual exposure to customers, weigh the risks against the pressure to go to market, and make a data-driven decision regarding customer protection and organizational liability.

CEthics standards

Ethics standards guide behavior, but don't provide the specific technical details of identified security flaws or their impact, nor a framework for risk prioritization and mitigation.

DChange ma agement policy

A change management policy outlines procedures for managing changes to IT systems, but it doesn't detail the specific security risks or their implications for the new services.

Concept tested: Risk-Based Decision Making

Topics

#Risk Management#Security Governance#Strategic Decision Making#Data Protection

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice