nerdexam
Isaca

CGEIT · Question #667

An enterprise has learned of a new regulation that may impact delivery of one of its core technology services. Which of the following should be done FIRST?

The correct answer is D. Assess the risk associated with the new regulation.. When a new regulation may impact a core technology service, the initial step should be to assess the associated risks to understand its potential implications.

Submitted by chen.hong· Apr 18, 2026Risk Optimization

Question

An enterprise has learned of a new regulation that may impact delivery of one of its core technology services. Which of the following should be done FIRST?

Options

  • ARequest an action plan from the risk team.
  • BDetermine whether the board wants to comply with the regulation.
  • CUpdate the risk management framework.
  • DAssess the risk associated with the new regulation.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    8% (2)
  • D
    84% (21)

Why each option

When a new regulation may impact a core technology service, the initial step should be to assess the associated risks to understand its potential implications.

ARequest an action plan from the risk team.

Requesting an action plan without first understanding the specific risks is premature, as the risk team needs an assessment to formulate an effective plan.

BDetermine whether the board wants to comply with the regulation.

Determining compliance desires from the board should follow a preliminary assessment of the regulation's impact and risk, as the board needs information to make an informed decision.

CUpdate the risk management framework.

Updating the risk management framework is a broader, systemic change that comes after understanding specific new risks and determining if existing frameworks are adequate or need modification.

DAssess the risk associated with the new regulation.Correct

Before any other action, it is crucial to assess the risk associated with the new regulation to understand its potential impact, likelihood, and severity on the core technology service, which informs subsequent decisions. This initial assessment provides the necessary data for effective governance and response.

Concept tested: Initial risk assessment for new regulations

Source: https://learn.microsoft.com/en-us/compliance/regulatory/regulatory-compliance-guide-overview

Topics

#Risk Assessment#Regulatory Compliance#Risk Management Process#IT Risk

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice