CGEIT · Question #593
The board of an organization has been informed of possible cyberthreats. Which of the following should be the board's NEXT course of action?
The correct answer is D. Engage the CIO to evaluate the risk. Upon being informed of possible cyberthreats, the board's immediate next action should be to engage the CIO to evaluate the identified risks, leveraging their expertise to understand the implications.
Question
The board of an organization has been informed of possible cyberthreats. Which of the following should be the board's NEXT course of action?
Options
- AEvaluate the security incident response process
- BReevaluate the risk tolerance of the organization
- CAsk the CIO to report on a risk response
- DEngage the CIO to evaluate the risk
How the community answered
(27 responses)- A7% (2)
- B4% (1)
- C11% (3)
- D78% (21)
Why each option
Upon being informed of possible cyberthreats, the board's immediate next action should be to engage the CIO to evaluate the identified risks, leveraging their expertise to understand the implications.
Evaluating the security incident response process is a specific, detailed operational task that falls to IT management, not the board directly, and it comes after understanding the nature of the threats.
Reevaluating risk tolerance might be a long-term outcome, but it's premature before understanding the specifics of the current threats and their alignment with existing risk tolerance.
Asking for a report on a risk response implies that a response plan already exists or is being developed; the initial step is to evaluate the new threats to inform any response.
When the board is informed of possible cyberthreats, their role is to ensure proper governance and oversight, not to directly manage the technical details. Engaging the CIO is the appropriate next step because the CIO is responsible for IT strategy, operations, and risk management, making them the expert best positioned to evaluate the nature, scope, and potential impact of the cyberthreats on the organization. This evaluation forms the basis for subsequent strategic decisions.
Concept tested: Board's role in cyber risk governance
Topics
Community Discussion
No community discussion yet for this question.