CGEIT · Question #398
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
The correct answer is D. Impact on business. When resource requirements for IT risk remediation are equal, the BEST criterion for prioritization is the potential impact on the business.
Question
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
Options
- ADeviation from IT standards
- BIT strategy alignment
- CIT audit recommendations
- DImpact on business
How the community answered
(22 responses)- A5% (1)
- C9% (2)
- D86% (19)
Why each option
When resource requirements for IT risk remediation are equal, the BEST criterion for prioritization is the potential impact on the business.
Deviation from IT standards indicates a compliance issue but does not inherently convey the business impact, which is a more critical prioritization factor.
While aligning with IT strategy is important for long-term goals, addressing risks with high business impact takes precedence in remediation prioritization, especially when resources are equal.
IT audit recommendations highlight areas for improvement, but their prioritization should still be based on their potential business impact, not just the fact that they were recommended by an audit.
Risks are ultimately managed to protect business value, so the severity of a risk's potential impact on business operations, finances, or reputation should be the primary factor in determining remediation priority when resources are not a constraint. This ensures that the most critical threats to the organization's mission are addressed first.
Concept tested: IT risk prioritization
Topics
Community Discussion
No community discussion yet for this question.