nerdexam
Isaca

CGEIT · Question #4

An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management…

The correct answer is C. determine if the new regulation introduces new risk. When a new privacy regulation is published, the IT risk management team's immediate priority is to assess its impact by determining if it introduces new risks or changes existing ones.

Submitted by khalil_dz· Apr 18, 2026Risk Optimization

Question

An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:

Options

  • Aevaluate the risk appetite for the new regulation.
  • Bdefine the risk tolerance for the new regulation.
  • Cdetermine if the new regulation introduces new risk.
  • Dassign a risk owner for the new regulation.

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    83% (25)
  • D
    3% (1)

Why each option

When a new privacy regulation is published, the IT risk management team's immediate priority is to assess its impact by determining if it introduces new risks or changes existing ones.

Aevaluate the risk appetite for the new regulation.

Evaluating risk appetite comes after understanding the risks introduced by the regulation, as appetite defines the level of risk the organization is willing to accept.

Bdefine the risk tolerance for the new regulation.

Defining risk tolerance, which specifies acceptable deviations from the risk appetite, is a later step, following the identification and assessment of new risks.

Cdetermine if the new regulation introduces new risk.Correct

The first step for an IT risk management team when a new regulation emerges is to determine its direct impact by identifying if it introduces new risks to the organization or significantly alters the nature or severity of existing risks related to PII. This assessment informs all subsequent risk management activities.

Dassign a risk owner for the new regulation.

Assigning a risk owner is important but typically follows the initial identification and assessment of the specific risks introduced by the new regulation.

Concept tested: Initial risk assessment for new regulations

Topics

#Risk Management Process#Regulatory Compliance#Risk Identification#IT Risk

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice