CGEIT · Question #409
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
The correct answer is A. Implement an IT risk management framework. Implementing an IT risk management framework is the best governance action to minimize the likelihood of IT failures jeopardizing corporate value by systematically identifying, assessing, and mitigating risks.
Question
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
Options
- AImplement an IT risk management framework.
- BInstall an IT continuous monitoring solution.
- CDefine IT performance management measures.
- DBenchmark IT strategy against industry peers.
How the community answered
(26 responses)- A73% (19)
- B4% (1)
- C8% (2)
- D15% (4)
Why each option
Implementing an IT risk management framework is the best governance action to minimize the likelihood of IT failures jeopardizing corporate value by systematically identifying, assessing, and mitigating risks.
An IT risk management framework provides a structured and systematic approach to identify, assess, respond to, monitor, and report on IT-related risks, directly addressing the goal of minimizing the likelihood of IT failures and their impact on corporate value. This holistic approach helps ensure that potential IT failures are proactively managed across the organization.
Installing an IT continuous monitoring solution is a control activity within a risk management framework, focusing on detection, but it doesn't encompass the full proactive management and response capabilities of a comprehensive framework.
Defining IT performance management measures helps track efficiency and effectiveness but is a reactive or measurement tool, not a proactive framework for preventing failures and managing risks to corporate value.
Benchmarking IT strategy helps identify gaps or opportunities for improvement compared to peers, but it's a strategic alignment activity and not a direct mechanism for managing and mitigating specific IT operational risks that could lead to failures.
Concept tested: IT risk management framework principles
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-risk-compliance
Topics
Community Discussion
No community discussion yet for this question.