nerdexam
Isaca

CGEIT · Question #663

Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:

The correct answer is C. Evaluate the impact of the emerging risk. The IT steering committee should first direct management to evaluate the full impact of the emerging regulatory risk, regardless of past enforcement, to inform strategic decisions.

Submitted by haruto_sh· Apr 18, 2026Risk Optimization

Question

Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:

Options

  • ADevelop mitigation plans for noncompliance.
  • BUpdate the enterprise architecture (EA).
  • CEvaluate the impact of the emerging risk.
  • DPerform benchmarking activities.

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    3% (1)
  • C
    72% (23)
  • D
    9% (3)

Why each option

The IT steering committee should first direct management to evaluate the full impact of the emerging regulatory risk, regardless of past enforcement, to inform strategic decisions.

ADevelop mitigation plans for noncompliance.

Developing mitigation plans for noncompliance prematurely assumes a decision has been made about compliance without a full understanding of the risk's actual impact.

BUpdate the enterprise architecture (EA).

Updating the enterprise architecture is a significant technical and strategic change that should only be considered after a thorough assessment of the risk impact and required response.

CEvaluate the impact of the emerging risk.Correct

Even with a history of weak enforcement, the potential for costly penalties means the new regulations represent an emerging risk. The first step in addressing any risk is to evaluate its potential impact, including financial, reputational, and operational consequences, to determine the appropriate response and level of resources to allocate to it. This evaluation informs whether the weak enforcement history makes the risk acceptable or if mitigation is still warranted due to the severity of potential penalties.

DPerform benchmarking activities.

Benchmarking activities might provide context but do not substitute for a direct internal evaluation of the specific impact these regulations would have on the enterprise.

Concept tested: Risk assessment and emerging IT risks

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/top-10-security-best-practices#1-risk-assessment

Topics

#Risk assessment#Emerging risk#Regulatory compliance#IT governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice