nerdexam
Isaca

CGEIT · Question #649

When developing IT risk management policies and standards, it is MOST important to align them with:

The correct answer is C. Enterprise goals and objectives. IT risk management policies and standards must primarily align with enterprise goals and objectives to ensure that risk mitigation efforts support overall business strategy.

Submitted by weili_xi· Apr 18, 2026Governance of Enterprise IT

Question

When developing IT risk management policies and standards, it is MOST important to align them with:

Options

  • ABest practices for IT risk management.
  • BThe corporate risk culture.
  • CEnterprise goals and objectives.
  • DThe enterprise risk management (ERM) framework.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    10% (4)
  • C
    83% (34)
  • D
    5% (2)

Why each option

IT risk management policies and standards must primarily align with enterprise goals and objectives to ensure that risk mitigation efforts support overall business strategy.

ABest practices for IT risk management.

While best practices are valuable, they should be adapted to the specific enterprise context and its objectives, rather than being the primary alignment factor.

BThe corporate risk culture.

Corporate risk culture is important for successful implementation, but the *policies themselves* must first align with the tangible goals and objectives the enterprise aims to achieve.

CEnterprise goals and objectives.Correct

Aligning IT risk management policies and standards with enterprise goals and objectives is paramount because it ensures that risk mitigation activities directly support the organization's strategic priorities and mission, making risk management a strategic enabler rather than just a compliance function. This ensures that resources are allocated to protect what is most critical to the business.

DThe enterprise risk management (ERM) framework.

The ERM framework provides the overarching structure for risk management, but IT risk policies must align directly with the specific *goals and objectives* that the ERM framework itself is designed to protect and support.

Concept tested: IT risk management alignment with business

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/security-governance-strategy#risk-tolerance

Topics

#IT Risk Management Policies#Strategic Alignment#Enterprise Goals#Governance Principles

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice