nerdexam
Isaca

CGEIT · Question #641

What is the BEST way for a board of directors to improve its ability to identify material changes to the enterprise IT risk profile?

The correct answer is C. Review the key risk indicators (KRIs) on a regular basis.. The best way for a board to identify material changes to the IT risk profile is by regularly reviewing Key Risk Indicators (KRIs), which are specific metrics designed to signal increasing or decreasing risk exposure. KRIs provide proactive insights into potential risk shifts.

Submitted by layla.eg· Apr 18, 2026Governance of Enterprise IT

Question

What is the BEST way for a board of directors to improve its ability to identify material changes to the enterprise IT risk profile?

Options

  • ARequire management to present a comprehensive list of risks.
  • BRequire the implementation of a security incident and event management (SIEM) tool.
  • CReview the key risk indicators (KRIs) on a regular basis.
  • DFocus on key performance indicators (KPIs) that predict future business performance.

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    5% (1)
  • C
    68% (13)
  • D
    16% (3)

Why each option

The best way for a board to identify material changes to the IT risk profile is by regularly reviewing Key Risk Indicators (KRIs), which are specific metrics designed to signal increasing or decreasing risk exposure. KRIs provide proactive insights into potential risk shifts.

ARequire management to present a comprehensive list of risks.

A comprehensive list of risks is static and a snapshot; it doesn't dynamically show *changes* in the risk profile over time.

BRequire the implementation of a security incident and event management (SIEM) tool.

A SIEM tool is an operational security technology; while crucial for incident management, its implementation is a management responsibility, not the board's primary way to *identify* changes at a strategic level.

CReview the key risk indicators (KRIs) on a regular basis.Correct

Key Risk Indicators (KRIs) are metrics that provide an early signal of increasing or decreasing risk exposure, helping management and the board to proactively monitor potential threats and vulnerabilities. Regular review of KRIs allows the board to understand trends and identify material changes in the enterprise's IT risk profile before they escalate into significant incidents, enabling timely strategic adjustments.

DFocus on key performance indicators (KPIs) that predict future business performance.

Key Performance Indicators (KPIs) measure organizational performance and progress towards objectives; while related, they do not directly focus on identifying changes in the *risk profile* as explicitly as KRIs do.

Concept tested: IT risk management and KRIs for board oversight

Topics

#Board oversight#IT Risk monitoring#Key Risk Indicators (KRIs)#Enterprise IT Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice