CGEIT · Question #516
Which of the following is necessary for effective risk management in IT governance?
The correct answer is A. Risk evaluation is embedded in the management processes.. For effective IT risk management within governance, risk evaluation must be integrated directly into routine management processes rather than being a separate or isolated activity.
Question
Which of the following is necessary for effective risk management in IT governance?
Options
- ARisk evaluation is embedded in the management processes.
- BIT risk management is separate from enterprise risk management (ERM).
- CLocal managers are solely responsible for risk evaluation.
- DRisk management strategy is approved by the audit committee.
How the community answered
(34 responses)- A88% (30)
- B3% (1)
- C9% (3)
Why each option
For effective IT risk management within governance, risk evaluation must be integrated directly into routine management processes rather than being a separate or isolated activity.
Embedding risk evaluation in management processes ensures that risks are continuously identified, assessed, and responded to as an integral part of daily operations and decision-making, leading to proactive and effective risk mitigation across the organization.
IT risk management should be integrated with enterprise risk management (ERM) to provide a holistic view of risks and ensure alignment with overall business objectives, not separated.
While local managers play a role, risk evaluation is a shared responsibility across various levels and functions within an organization, not solely confined to local managers.
While the audit committee may oversee risk management, approval of the risk management strategy is typically a responsibility of senior management or the board, ensuring it aligns with strategic objectives.
Concept tested: Integrating IT risk management into business processes
Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-management-framework
Topics
Community Discussion
No community discussion yet for this question.