nerdexam
Isaca

CGEIT · Question #593

The board of an organization has been informed of possible cyberthreats. Which of the following should be the board's NEXT course of action?

The correct answer is D. Engage the CIO to evaluate the risk. Upon being informed of possible cyberthreats, the board's immediate next action should be to engage the CIO to evaluate the identified risks, leveraging their expertise to understand the implications.

Submitted by valeria.br· Apr 18, 2026Governance of Enterprise IT

Question

The board of an organization has been informed of possible cyberthreats. Which of the following should be the board's NEXT course of action?

Options

  • AEvaluate the security incident response process
  • BReevaluate the risk tolerance of the organization
  • CAsk the CIO to report on a risk response
  • DEngage the CIO to evaluate the risk

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    11% (3)
  • D
    78% (21)

Why each option

Upon being informed of possible cyberthreats, the board's immediate next action should be to engage the CIO to evaluate the identified risks, leveraging their expertise to understand the implications.

AEvaluate the security incident response process

Evaluating the security incident response process is a specific, detailed operational task that falls to IT management, not the board directly, and it comes after understanding the nature of the threats.

BReevaluate the risk tolerance of the organization

Reevaluating risk tolerance might be a long-term outcome, but it's premature before understanding the specifics of the current threats and their alignment with existing risk tolerance.

CAsk the CIO to report on a risk response

Asking for a report on a risk response implies that a response plan already exists or is being developed; the initial step is to evaluate the new threats to inform any response.

DEngage the CIO to evaluate the riskCorrect

When the board is informed of possible cyberthreats, their role is to ensure proper governance and oversight, not to directly manage the technical details. Engaging the CIO is the appropriate next step because the CIO is responsible for IT strategy, operations, and risk management, making them the expert best positioned to evaluate the nature, scope, and potential impact of the cyberthreats on the organization. This evaluation forms the basis for subsequent strategic decisions.

Concept tested: Board's role in cyber risk governance

Topics

#Board oversight#Cybersecurity governance#Risk evaluation#CIO engagement

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice