nerdexam
Isaca

CGEIT · Question #594

When developing IT risk management policies and standards, it is MOST important to align them with:

The correct answer is B. The enterprise risk management (ERM) framework. When developing IT risk management policies and standards, it is most important to align them with the overarching enterprise risk management (ERM) framework to ensure consistency and holistic risk governance across the organization.

Submitted by tunde_lagos· Apr 18, 2026Governance of Enterprise IT

Question

When developing IT risk management policies and standards, it is MOST important to align them with:

Options

  • AThe corporate risk culture
  • BThe enterprise risk management (ERM) framework
  • CEnterprise goals and objectives
  • DBest practices for IT risk management

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    91% (53)
  • C
    5% (3)
  • D
    2% (1)

Why each option

When developing IT risk management policies and standards, it is most important to align them with the overarching enterprise risk management (ERM) framework to ensure consistency and holistic risk governance across the organization.

AThe corporate risk culture

While corporate risk culture influences risk management, the ERM framework provides the structured governance and methodology that policies and standards should follow.

BThe enterprise risk management (ERM) frameworkCorrect

The Enterprise Risk Management (ERM) framework provides a comprehensive, integrated approach to managing risks across all functions and levels of an organization. Aligning IT risk management policies and standards with the ERM framework ensures that IT risks are identified, assessed, and managed within the broader context of organizational objectives and risk appetite, preventing silos and promoting a unified risk posture.

CEnterprise goals and objectives

Enterprise goals and objectives are critical drivers for ERM, but the ERM framework is the specific mechanism for translating these goals into actionable risk management policies and standards.

DBest practices for IT risk management

Best practices for IT risk management are valuable guides, but they should be adapted and integrated within the organization's specific ERM framework, not adopted in isolation.

Concept tested: IT risk management alignment with ERM

Topics

#IT Risk Management#ERM Framework#Policies and Standards#Alignment

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice