nerdexam
Isaca

CGEIT · Question #51

Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?

The correct answer is D. Enterprise definitions for risk impact and probability. Before an IT strategy committee can approve a risk assessment framework, it is most important to have established enterprise-wide definitions for risk impact and probability to ensure consistent evaluation.

Submitted by naveen.iyer· Apr 18, 2026Risk Optimization

Question

Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?

Options

  • AAn enterprise risk mitigation strategy
  • BLeading and lagging risk indicators
  • CIT performance metrics and standards
  • DEnterprise definitions for risk impact and probability

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    8% (2)
  • C
    24% (6)
  • D
    56% (14)

Why each option

Before an IT strategy committee can approve a risk assessment framework, it is most important to have established enterprise-wide definitions for risk impact and probability to ensure consistent evaluation.

AAn enterprise risk mitigation strategy

An enterprise risk mitigation strategy is an outcome of a risk assessment and analysis process, not a prerequisite for approving the framework itself.

BLeading and lagging risk indicators

Leading and lagging risk indicators are used to monitor and measure risk over time, which comes after the risk assessment framework is established and operationalized.

CIT performance metrics and standards

IT performance metrics and standards relate to operational efficiency and effectiveness, which are separate from the foundational definitions required for a risk assessment framework.

DEnterprise definitions for risk impact and probabilityCorrect

Establishing enterprise definitions for risk impact and probability is fundamental because it provides a common language and standardized criteria for evaluating risks across the entire organization. This ensures that all stakeholders, including the IT strategy committee, have a consistent understanding of what constitutes a 'high,' 'medium,' or 'low' risk, allowing for meaningful aggregation and comparison of risks within the framework. Without these definitions, risk assessments would be subjective and inconsistent.

Concept tested: IT risk assessment framework prerequisites

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#IT Risk Assessment#Risk Framework#Risk Definitions#Risk Management Foundations

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice