nerdexam
Isaca

CGEIT · Question #516

Which of the following is necessary for effective risk management in IT governance?

The correct answer is A. Risk evaluation is embedded in the management processes.. For effective IT risk management within governance, risk evaluation must be integrated directly into routine management processes rather than being a separate or isolated activity.

Submitted by femi9· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is necessary for effective risk management in IT governance?

Options

  • ARisk evaluation is embedded in the management processes.
  • BIT risk management is separate from enterprise risk management (ERM).
  • CLocal managers are solely responsible for risk evaluation.
  • DRisk management strategy is approved by the audit committee.

How the community answered

(34 responses)
  • A
    88% (30)
  • B
    3% (1)
  • C
    9% (3)

Why each option

For effective IT risk management within governance, risk evaluation must be integrated directly into routine management processes rather than being a separate or isolated activity.

ARisk evaluation is embedded in the management processes.Correct

Embedding risk evaluation in management processes ensures that risks are continuously identified, assessed, and responded to as an integral part of daily operations and decision-making, leading to proactive and effective risk mitigation across the organization.

BIT risk management is separate from enterprise risk management (ERM).

IT risk management should be integrated with enterprise risk management (ERM) to provide a holistic view of risks and ensure alignment with overall business objectives, not separated.

CLocal managers are solely responsible for risk evaluation.

While local managers play a role, risk evaluation is a shared responsibility across various levels and functions within an organization, not solely confined to local managers.

DRisk management strategy is approved by the audit committee.

While the audit committee may oversee risk management, approval of the risk management strategy is typically a responsibility of senior management or the board, ensuring it aligns with strategic objectives.

Concept tested: Integrating IT risk management into business processes

Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-management-framework

Topics

#Risk Management#IT Governance#Process Integration#Enterprise Risk Management

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice