CGEIT · Question #25
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
The correct answer is C. Ensuring IT risk management is aligned with business risk appetite. The primary ongoing responsibility of the IT governance function related to risk is ensuring that IT risk management is aligned with the overall business risk appetite.
Question
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
Options
- AResponding to and controlling all IT risk events
- BCommunicating the enterprise risk management plan
- CEnsuring IT risk management is aligned with business risk appetite
- DVerifying that all business units have staff skilled at assessing risk
How the community answered
(25 responses)- B4% (1)
- C92% (23)
- D4% (1)
Why each option
The primary ongoing responsibility of the IT governance function related to risk is ensuring that IT risk management is aligned with the overall business risk appetite.
Responding to and controlling individual IT risk events is an operational function, typically handled by IT management or security teams, not the strategic IT governance function.
Communicating the enterprise risk management plan is a task performed by various parties, but the primary ongoing responsibility of IT governance is the strategic alignment of IT risk.
IT governance's primary responsibility related to risk is to ensure that IT risk management strategies and activities are consistently aligned with the organization's overarching business risk appetite, providing strategic oversight rather than operational execution.
Verifying staff skills is an important management task, but it is not the primary ongoing responsibility of strategic IT governance concerning risk alignment.
Concept tested: IT Governance and Risk Alignment
Source: https://www.isaca.org/resources/it-governance/it-risk
Topics
Community Discussion
No community discussion yet for this question.