nerdexam
Isaca

CGEIT · Question #442

A newly hired IT director of a large international enterprise has been asked to provide periodic updates regarding IT risk to the board. Which of the following is the MOST effective way to initially…

The correct answer is B. Include key IT risks in a dashboard submitted to the board quarterly. To effectively address the board's request for IT risk updates, the IT director should initially provide a concise dashboard of key IT risks quarterly.

Submitted by lars.no· Apr 18, 2026Governance of Enterprise IT

Question

A newly hired IT director of a large international enterprise has been asked to provide periodic updates regarding IT risk to the board. Which of the following is the MOST effective way to initially address this request?

Options

  • AInclude a complete IT risk register in the monthly letter given to each board member.
  • BInclude key IT risks in a dashboard submitted to the board quarterly.
  • CSubmit a register of all IT audit findings to board members monthly.
  • DSchedule quarterly meetings to discuss all open IT risks.

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    77% (24)
  • C
    13% (4)
  • D
    3% (1)

Why each option

To effectively address the board's request for IT risk updates, the IT director should initially provide a concise dashboard of key IT risks quarterly.

AInclude a complete IT risk register in the monthly letter given to each board member.

Providing a complete IT risk register monthly would be too detailed and frequent for board members, who typically require summarized, strategic information, not operational level data.

BInclude key IT risks in a dashboard submitted to the board quarterly.Correct

Presenting key IT risks in a quarterly dashboard is most effective because it provides the board with a high-level, focused summary of the most critical risks relevant to their strategic oversight, without overwhelming them with excessive detail. Quarterly updates offer appropriate periodicity for strategic governance, allowing for meaningful trends and mitigation efforts to be observed.

CSubmit a register of all IT audit findings to board members monthly.

Submitting only IT audit findings is too narrow, as it covers past issues and not the broader ongoing IT risk landscape that the board needs to understand for proactive governance.

DSchedule quarterly meetings to discuss all open IT risks.

Scheduling quarterly meetings to discuss all open IT risks could be overly time-consuming and inefficient; a summarized dashboard allows for focused discussion on the most critical items, with the option to deep dive if needed.

Concept tested: IT risk reporting and governance communication

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-reporting

Topics

#IT Risk Reporting#Board Communication#Executive Dashboards#IT Governance Oversight

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice