CGEIT · Question #51
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
The correct answer is D. Enterprise definitions for risk impact and probability. Before an IT strategy committee can approve a risk assessment framework, it is most important to have established enterprise-wide definitions for risk impact and probability to ensure consistent evaluation.
Question
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
Options
- AAn enterprise risk mitigation strategy
- BLeading and lagging risk indicators
- CIT performance metrics and standards
- DEnterprise definitions for risk impact and probability
How the community answered
(25 responses)- A12% (3)
- B8% (2)
- C24% (6)
- D56% (14)
Why each option
Before an IT strategy committee can approve a risk assessment framework, it is most important to have established enterprise-wide definitions for risk impact and probability to ensure consistent evaluation.
An enterprise risk mitigation strategy is an outcome of a risk assessment and analysis process, not a prerequisite for approving the framework itself.
Leading and lagging risk indicators are used to monitor and measure risk over time, which comes after the risk assessment framework is established and operationalized.
IT performance metrics and standards relate to operational efficiency and effectiveness, which are separate from the foundational definitions required for a risk assessment framework.
Establishing enterprise definitions for risk impact and probability is fundamental because it provides a common language and standardized criteria for evaluating risks across the entire organization. This ensures that all stakeholders, including the IT strategy committee, have a consistent understanding of what constitutes a 'high,' 'medium,' or 'low' risk, allowing for meaningful aggregation and comparison of risks within the framework. Without these definitions, risk assessments would be subjective and inconsistent.
Concept tested: IT risk assessment framework prerequisites
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.