CGEIT · Question #654
Which of the following will BEST help to ensure enterprise IT risk is effectively managed?
The correct answer is B. Establishing roles and responsibilities for IT risk at the senior management level. Effectively managing enterprise IT risk is best achieved by establishing clear roles and responsibilities for IT risk at the senior management level, ensuring accountability and strategic oversight.
Question
Which of the following will BEST help to ensure enterprise IT risk is effectively managed?
Options
- AEstablishing an audit committee that reports to the board
- BEstablishing roles and responsibilities for IT risk at the senior management level
- CIdentifying the lowest IT risks and outsourcing the related IT functions
- DAssigning a project sponsor and project manager to implement an IT risk register
How the community answered
(35 responses)- A9% (3)
- B74% (26)
- C3% (1)
- D14% (5)
Why each option
Effectively managing enterprise IT risk is best achieved by establishing clear roles and responsibilities for IT risk at the senior management level, ensuring accountability and strategic oversight.
An audit committee reporting to the board provides oversight but does not directly establish the operational or strategic management of IT risk within the executive structure.
Establishing clear roles and responsibilities for IT risk at the senior management level is paramount because it ensures accountability for risk decisions, drives strategic prioritization of risk mitigation efforts, and embeds risk management into the enterprise's overall governance structure. This ensures IT risk is treated as a strategic business concern, not just an operational one.
Outsourcing low IT risks is a risk response strategy, but it does not ensure *effective management* of enterprise IT risk as a whole, nor does it address accountability for risk.
Assigning a project sponsor and project manager for an IT risk register helps implement a tool, but it doesn't establish the comprehensive governance and accountability for *managing* IT risk across the enterprise, especially at a strategic level.
Concept tested: IT risk governance and accountability
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/security-governance-strategy
Topics
Community Discussion
No community discussion yet for this question.