CGEIT · Question #27
Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?
The correct answer is A. The need to enable IT risk-aware decisions by executives. The main reason for an enterprise to implement an IT risk management framework is to enable executives to make informed, IT risk-aware decisions.
Question
Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?
Options
- AThe need to enable IT risk-aware decisions by executives
- BThe results of an external audit report concerning IT risk management processes
- CThe need to address market regulations and internal compliance in IT risk
- DThe ability to benchmark IT risk policies against major competitors
How the community answered
(14 responses)- A71% (10)
- B7% (1)
- C7% (1)
- D14% (2)
Why each option
The main reason for an enterprise to implement an IT risk management framework is to enable executives to make informed, IT risk-aware decisions.
The main reason to implement an IT risk management framework is to provide executives with the necessary insights and context to make informed, risk-aware decisions that balance potential threats with business opportunities and objectives.
While external audit findings can prompt the implementation of an IT risk framework, they are not the main reason or fundamental benefit of having one.
Addressing regulations and compliance is an important driver, but it is a subset of enabling risk-aware decisions rather than the primary, overarching strategic benefit of the framework.
Benchmarking against competitors can be a useful exercise, but it is not the core strategic driver for establishing an internal IT risk management framework.
Concept tested: Purpose of IT Risk Management Framework
Source: https://www.isaca.org/resources/it-governance/it-risk
Topics
Community Discussion
No community discussion yet for this question.