nerdexam
Isaca

CGEIT · Question #376

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

The correct answer is B. risk management framework.. To ensure consistent IT risk management, IT governance must establish a comprehensive risk management framework that defines the approach, policies, and processes for identifying, assessing, responding to, and monitoring risks. This framework provides the foundational structure f

Submitted by jakub_pl· Apr 18, 2026Governance of Enterprise IT

Question

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

Options

  • Arisk management committee to identify IT-related risks.
  • Brisk management framework.
  • Cbalanced scorecard that includes IT risks.
  • Drisk management reporting tool to ensure compliance.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    88% (35)
  • C
    3% (1)
  • D
    8% (3)

Why each option

To ensure consistent IT risk management, IT governance must establish a comprehensive risk management framework that defines the approach, policies, and processes for identifying, assessing, responding to, and monitoring risks. This framework provides the foundational structure for all risk activities.

Arisk management committee to identify IT-related risks.

A risk management committee is a component of a framework but doesn't, by itself, ensure consistent management without defined processes and policies.

Brisk management framework.Correct

A risk management framework, such as ISO 31000 or NIST RMF, provides the overarching structure, principles, and processes for managing risk consistently across an organization. It establishes the context, risk assessment methodology, treatment options, monitoring, and reporting mechanisms, ensuring a standardized and repeatable approach to IT risk management.

Cbalanced scorecard that includes IT risks.

A balanced scorecard is a performance management tool that might include risk metrics but does not establish the fundamental methodology for consistent risk management.

Drisk management reporting tool to ensure compliance.

A risk management reporting tool is an operational instrument that supports a framework but does not define the consistent management approach itself.

Concept tested: IT Risk Management Framework Establishment

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-37r2.pdf

Topics

#IT Governance#IT Risk Management#Risk Framework#Consistency

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice