CGEIT · Question #361
An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
The correct answer is C. The enterprise risk appetite. Before establishing Key Risk Indicators (KRIs) to manage IT risk, an enterprise must first identify its risk appetite to define acceptable risk levels.
Question
An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
Options
- ARisk mitigation strategies
- BEnterprise architecture (EA) components
- CThe enterprise risk appetite
- DKey performance metrics
How the community answered
(56 responses)- A4% (2)
- C95% (53)
- D2% (1)
Why each option
Before establishing Key Risk Indicators (KRIs) to manage IT risk, an enterprise must first identify its risk appetite to define acceptable risk levels.
Risk mitigation strategies are actions taken to reduce identified risks; identifying these comes after understanding the risk landscape and appetite.
Enterprise architecture components are part of the context for risk, but do not dictate the fundamental thresholds or boundaries for risk tolerance that KRIs are built upon.
The enterprise risk appetite defines the overall level of risk an organization is prepared to accept in pursuit of its objectives. Identifying this first is crucial because KRIs are designed to monitor whether the actual risk exposure is approaching or exceeding this defined appetite, making the appetite the fundamental baseline for KRI development.
Key performance metrics measure operational success, not the organization's tolerance for risk or early warnings of risk exposure.
Concept tested: KRI development prerequisites
Source: https://learn.microsoft.com/en-us/industry/financial/enterprise-risk-management-strategies-for-financial-institutions-architecture-guide#enterprise-risk-indicators
Topics
Community Discussion
No community discussion yet for this question.