CGEIT · Question #320
Before establishing IT key risk indicators (KRls) which of the following should be defined FIRST?
The correct answer is C. IT goals and objectives. Before establishing IT Key Risk Indicators (KRIs), the organization's IT goals and objectives must be defined first to ensure KRIs are relevant to achieving strategic aims.
Question
Before establishing IT key risk indicators (KRls) which of the following should be defined FIRST?
Options
- AIT resource strategy
- BIT risk and security framework
- CIT goals and objectives
- DIT key performance indicators (KPIs)
How the community answered
(42 responses)- B2% (1)
- C93% (39)
- D5% (2)
Why each option
Before establishing IT Key Risk Indicators (KRIs), the organization's IT goals and objectives must be defined first to ensure KRIs are relevant to achieving strategic aims.
An IT resource strategy outlines how resources will be acquired and managed, but it does not establish the fundamental targets against which risks are measured.
An IT risk and security framework provides the structure for managing risk, but the content of what constitutes a risk is derived from the goals that need protection.
IT goals and objectives must be defined first because KRIs are measures that signal potential threats to the achievement of those specific goals and objectives. Without clear targets, it is impossible to identify what constitutes a risk or what indicators would be relevant for monitoring deviations from the desired outcomes, making goal definition foundational for effective risk management.
IT Key Performance Indicators (KPIs) measure progress towards goals, whereas KRIs predict potential future problems, and both rely on the prior definition of the underlying goals.
Concept tested: Prerequisite for IT KRI definition
Topics
Community Discussion
No community discussion yet for this question.