CGEIT · Question #682
When establishing a comprehensive approach for analyzing IT risk in an international, multi- division enterprise, it is MOST important to ensure:
The correct answer is D. A consistent risk management methodology is used. For an international, multi-division enterprise, the most crucial aspect of a comprehensive IT risk analysis is ensuring a consistent risk management methodology across all divisions. This consistency enables accurate aggregation, comparison, and holistic management of risks.
Question
When establishing a comprehensive approach for analyzing IT risk in an international, multi- division enterprise, it is MOST important to ensure:
Options
- ARisk management methodologies are aligned with local best practices.
- BIT senior managers perform the analysis.
- CRisk scenarios are compartmentalized by division.
- DA consistent risk management methodology is used.
How the community answered
(32 responses)- A9% (3)
- B3% (1)
- C3% (1)
- D84% (27)
Why each option
For an international, multi-division enterprise, the most crucial aspect of a comprehensive IT risk analysis is ensuring a consistent risk management methodology across all divisions. This consistency enables accurate aggregation, comparison, and holistic management of risks.
While aligning with local best practices can be beneficial, it can lead to disparate methodologies across divisions, making comprehensive, enterprise-wide risk aggregation and comparison difficult.
While IT senior managers should be involved in risk analysis, mandating that they *perform* all analysis is not the most important factor for comprehensiveness or consistency; trained professionals using a defined methodology are key.
Compartmentalizing risk scenarios by division without a consistent overarching methodology prevents an aggregated, enterprise-wide view of IT risk and potential interdependencies.
In an international, multi-division enterprise, using a consistent risk management methodology is paramount for a comprehensive IT risk analysis. Consistency ensures that risks are identified, assessed, and reported uniformly across all divisions and geographies, allowing for accurate aggregation, comparison, and holistic management of the enterprise's overall risk posture.
Concept tested: Enterprise IT risk management consistency
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/risk-compliance-strategy
Topics
Community Discussion
No community discussion yet for this question.