nerdexam
Isaca

CGEIT · Question #682

When establishing a comprehensive approach for analyzing IT risk in an international, multi- division enterprise, it is MOST important to ensure:

The correct answer is D. A consistent risk management methodology is used. For an international, multi-division enterprise, the most crucial aspect of a comprehensive IT risk analysis is ensuring a consistent risk management methodology across all divisions. This consistency enables accurate aggregation, comparison, and holistic management of risks.

Submitted by femi9· Apr 18, 2026Risk Optimization

Question

When establishing a comprehensive approach for analyzing IT risk in an international, multi- division enterprise, it is MOST important to ensure:

Options

  • ARisk management methodologies are aligned with local best practices.
  • BIT senior managers perform the analysis.
  • CRisk scenarios are compartmentalized by division.
  • DA consistent risk management methodology is used.

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    84% (27)

Why each option

For an international, multi-division enterprise, the most crucial aspect of a comprehensive IT risk analysis is ensuring a consistent risk management methodology across all divisions. This consistency enables accurate aggregation, comparison, and holistic management of risks.

ARisk management methodologies are aligned with local best practices.

While aligning with local best practices can be beneficial, it can lead to disparate methodologies across divisions, making comprehensive, enterprise-wide risk aggregation and comparison difficult.

BIT senior managers perform the analysis.

While IT senior managers should be involved in risk analysis, mandating that they *perform* all analysis is not the most important factor for comprehensiveness or consistency; trained professionals using a defined methodology are key.

CRisk scenarios are compartmentalized by division.

Compartmentalizing risk scenarios by division without a consistent overarching methodology prevents an aggregated, enterprise-wide view of IT risk and potential interdependencies.

DA consistent risk management methodology is used.Correct

In an international, multi-division enterprise, using a consistent risk management methodology is paramount for a comprehensive IT risk analysis. Consistency ensures that risks are identified, assessed, and reported uniformly across all divisions and geographies, allowing for accurate aggregation, comparison, and holistic management of the enterprise's overall risk posture.

Concept tested: Enterprise IT risk management consistency

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/risk-compliance-strategy

Topics

#IT Risk Management#Risk Methodology#Enterprise Consistency

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice