Isaca
CGEIT · Question #497
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Sign in or unlock CGEIT to reveal the answer and full explanation for question #497. The question stem and answer options stay visible for context.
Submitted by omar99· Apr 18, 2026Governance of Enterprise IT
Question
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Options
- AOrganizational responsibility for IT risk management is not clearly defined.
- BNone of the members of the IT risk management team have risk management-related
- COnly a few key risk indicators (KRIs) identified by the IT risk management team are being
- DIT risk training records are not properly retained in accordance with established schedules
Unlock CGEIT to see the answer
You've previewed enough free CGEIT questions. Unlock CGEIT for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#IT Risk Management#Governance#Accountability#Organizational Structure