nerdexam
Isaca

CGEIT · Question #388

Which of the following should be identified FIRST when determining appropriate IT key risk indicators (KRIs)?

The correct answer is A. IT-related risk. To establish effective Key Risk Indicators (KRIs), one must first identify the specific IT-related risks that the organization faces. KRIs are designed to monitor these identified risks, indicating when they are approaching or exceeding the organization's risk appetite.

Submitted by devops_kid· Apr 18, 2026Risk Optimization

Question

Which of the following should be identified FIRST when determining appropriate IT key risk indicators (KRIs)?

Options

  • AIT-related risk
  • BIT controls
  • CIT threats
  • DIT objectives

How the community answered

(34 responses)
  • A
    85% (29)
  • B
    3% (1)
  • C
    3% (1)
  • D
    9% (3)

Why each option

To establish effective Key Risk Indicators (KRIs), one must first identify the specific IT-related risks that the organization faces. KRIs are designed to monitor these identified risks, indicating when they are approaching or exceeding the organization's risk appetite.

AIT-related riskCorrect

Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposure; therefore, the specific risks that need monitoring must be identified first. Without clearly defined IT-related risks, it's impossible to establish relevant indicators that effectively signal potential issues.

BIT controls

IT controls are implemented to mitigate risks, and their effectiveness might be monitored by KRIs, but controls themselves are not the starting point for identifying what to measure with KRIs.

CIT threats

IT threats are a component of risk (threat + vulnerability = risk), but the comprehensive IT-related risk, which includes assets and impact, must be understood before defining indicators.

DIT objectives

While IT objectives are foundational to risk management, the direct input for KRIs is the specific risks that could prevent those objectives from being met.

Concept tested: Identifying IT risks for KRI development

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-assessment

Topics

#Key Risk Indicators (KRIs)#Risk Identification#IT Risk Management#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice