CGEIT · Question #66
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
The correct answer is D. the impact of IT risk to the enterprise is managed.. The primary goal of an IT risk optimization process, from a governance perspective, is to ensure the overall impact of IT risk to the enterprise is effectively managed.
Question
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
Options
- AIT risk thresholds are defined in the enterprise architecture (EA).
- Bthe IT risk mitigation strategy is approved by management.
- CIT risk is mapped to the balanced scorecard.
- Dthe impact of IT risk to the enterprise is managed.
How the community answered
(51 responses)- A4% (2)
- B8% (4)
- C2% (1)
- D86% (44)
Why each option
The primary goal of an IT risk optimization process, from a governance perspective, is to ensure the overall impact of IT risk to the enterprise is effectively managed.
Defining risk thresholds in the EA is a specific implementation detail of risk management, not the overarching primary goal of risk optimization itself.
Approving the IT risk mitigation strategy by management is a necessary step in the risk management process, but the ultimate goal is broader: managing the impact of those risks.
Mapping IT risk to the balanced scorecard is a reporting and measurement mechanism, not the primary goal of the risk optimization process itself, which focuses on control and impact.
Risk optimization aims to balance the costs and benefits of risk responses, ensuring that the enterprise accepts an appropriate level of risk and that its adverse impacts are controlled and within defined tolerance levels, aligning with business objectives.
Concept tested: IT Risk Management and Governance Objectives
Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-governance-and-management-objectives
Topics
Community Discussion
No community discussion yet for this question.