CGEIT · Question #406
When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:
The correct answer is B. risk profile of the enterprise.. When conducting a risk assessment for a new regulatory requirement, the IT risk committee should first consider the overall risk profile of the enterprise to understand the existing risk landscape and potential impact.
Question
When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:
Options
- Adisruption to normal business operations.
- Brisk profile of the enterprise.
- Creadiness of IT systems to address
- Dthe risk cost burden to achieve compliance.
How the community answered
(33 responses)- A3% (1)
- B73% (24)
- C15% (5)
- D9% (3)
Why each option
When conducting a risk assessment for a new regulatory requirement, the IT risk committee should first consider the overall risk profile of the enterprise to understand the existing risk landscape and potential impact.
Disruptions to normal business operations are a potential impact of non-compliance or implementing new controls, which is assessed after understanding the initial risk profile.
The enterprise's existing risk profile provides a foundational understanding of the organization's overall risk appetite, current threats, vulnerabilities, and controls, which is crucial context before assessing risks specific to a new regulatory requirement. This initial understanding helps in scoping the assessment and aligning it with the enterprise's broader risk management strategy.
Assessing the readiness of IT systems is a detailed step in identifying specific vulnerabilities or gaps, which follows the broader understanding of the enterprise risk profile.
The risk cost burden is a factor in risk treatment and decision-making, but it comes after the identification and analysis of risks in the context of the enterprise's overall risk posture.
Concept tested: Enterprise risk management foundational steps
Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/security-governance-risk-compliance#risk-assessment
Topics
Community Discussion
No community discussion yet for this question.