nerdexam
Isaca

CGEIT · Question #665

An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?

The correct answer is A. Risk appetite of the enterprise. When defining a risk management policy for IT investments, the enterprise's overall risk appetite is the primary consideration, as it dictates the acceptable level of risk for all related decisions.

Submitted by ashley.k· Apr 18, 2026Governance of Enterprise IT

Question

An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?

Options

  • ARisk appetite of the enterprise.
  • BPossible investment failures.
  • CRisk management framework.
  • DValue obtained with minimum risk.

How the community answered

(21 responses)
  • A
    86% (18)
  • B
    10% (2)
  • D
    5% (1)

Why each option

When defining a risk management policy for IT investments, the enterprise's overall risk appetite is the primary consideration, as it dictates the acceptable level of risk for all related decisions.

ARisk appetite of the enterprise.Correct

The enterprise's risk appetite defines the overall level of risk the organization is willing to accept or tolerate to achieve its objectives. When developing a risk management policy for IT investments, this overarching parameter is the fundamental guiding principle, as it sets the boundaries and expectations for all subsequent risk identification, assessment, and treatment strategies within the investment portfolio.

BPossible investment failures.

Possible investment failures are specific risks that need to be managed, but the approach to managing them is dictated by the broader risk appetite.

CRisk management framework.

A risk management framework provides the structure and processes for managing risk, but the direction and tolerance for risk within that framework are set by the risk appetite.

DValue obtained with minimum risk.

While aiming for value with minimum risk is a goal, the specific definition of 'minimum risk' and the acceptable trade-offs are ultimately determined by the enterprise's risk appetite.

Concept tested: Risk appetite as foundational governance

Topics

#Risk management policy#Risk appetite#IT governance committee#Strategic risk management

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice