nerdexam
Isaca

CGEIT · Question #320

Before establishing IT key risk indicators (KRls) which of the following should be defined FIRST?

The correct answer is C. IT goals and objectives. Before establishing IT Key Risk Indicators (KRIs), the organization's IT goals and objectives must be defined first to ensure KRIs are relevant to achieving strategic aims.

Submitted by saadiq_pk· Apr 18, 2026Governance of Enterprise IT

Question

Before establishing IT key risk indicators (KRls) which of the following should be defined FIRST?

Options

  • AIT resource strategy
  • BIT risk and security framework
  • CIT goals and objectives
  • DIT key performance indicators (KPIs)

How the community answered

(42 responses)
  • B
    2% (1)
  • C
    93% (39)
  • D
    5% (2)

Why each option

Before establishing IT Key Risk Indicators (KRIs), the organization's IT goals and objectives must be defined first to ensure KRIs are relevant to achieving strategic aims.

AIT resource strategy

An IT resource strategy outlines how resources will be acquired and managed, but it does not establish the fundamental targets against which risks are measured.

BIT risk and security framework

An IT risk and security framework provides the structure for managing risk, but the content of what constitutes a risk is derived from the goals that need protection.

CIT goals and objectivesCorrect

IT goals and objectives must be defined first because KRIs are measures that signal potential threats to the achievement of those specific goals and objectives. Without clear targets, it is impossible to identify what constitutes a risk or what indicators would be relevant for monitoring deviations from the desired outcomes, making goal definition foundational for effective risk management.

DIT key performance indicators (KPIs)

IT Key Performance Indicators (KPIs) measure progress towards goals, whereas KRIs predict potential future problems, and both rely on the prior definition of the underlying goals.

Concept tested: Prerequisite for IT KRI definition

Topics

#IT Governance#Risk Management Framework#Strategic Alignment#IT Objectives

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice