CGEIT · Question #663
Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:
The correct answer is C. Evaluate the impact of the emerging risk. The IT steering committee should first direct management to evaluate the full impact of the emerging regulatory risk, regardless of past enforcement, to inform strategic decisions.
Question
Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:
Options
- ADevelop mitigation plans for noncompliance.
- BUpdate the enterprise architecture (EA).
- CEvaluate the impact of the emerging risk.
- DPerform benchmarking activities.
How the community answered
(32 responses)- A16% (5)
- B3% (1)
- C72% (23)
- D9% (3)
Why each option
The IT steering committee should first direct management to evaluate the full impact of the emerging regulatory risk, regardless of past enforcement, to inform strategic decisions.
Developing mitigation plans for noncompliance prematurely assumes a decision has been made about compliance without a full understanding of the risk's actual impact.
Updating the enterprise architecture is a significant technical and strategic change that should only be considered after a thorough assessment of the risk impact and required response.
Even with a history of weak enforcement, the potential for costly penalties means the new regulations represent an emerging risk. The first step in addressing any risk is to evaluate its potential impact, including financial, reputational, and operational consequences, to determine the appropriate response and level of resources to allocate to it. This evaluation informs whether the weak enforcement history makes the risk acceptable or if mitigation is still warranted due to the severity of potential penalties.
Benchmarking activities might provide context but do not substitute for a direct internal evaluation of the specific impact these regulations would have on the enterprise.
Concept tested: Risk assessment and emerging IT risks
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/top-10-security-best-practices#1-risk-assessment
Topics
Community Discussion
No community discussion yet for this question.