nerdexam
Isaca

CGEIT · Question #84

An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?

The correct answer is A. Incident severity and downtime trend analysis. To measure progress in improving system availability to mitigate IT risk, the most important data to report to the CIO would be incident severity and downtime trend analysis. These metrics directly reflect the system's operational stability and the impact of availability issues.

Submitted by tom_us· Apr 18, 2026Governance of Enterprise IT

Question

An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?

Options

  • AIncident severity and downtime trend analysis
  • BProbability and seventy of each IT risk
  • CFinancial losses and bad press releases
  • DCustomer and stakeholder complaints over time

How the community answered

(48 responses)
  • A
    71% (34)
  • B
    4% (2)
  • C
    17% (8)
  • D
    8% (4)

Why each option

To measure progress in improving system availability to mitigate IT risk, the most important data to report to the CIO would be incident severity and downtime trend analysis. These metrics directly reflect the system's operational stability and the impact of availability issues.

AIncident severity and downtime trend analysisCorrect

Incident severity and downtime trend analysis directly measure the *impact* and *frequency* of system unavailability, which are precisely the aspects an effort to improve system availability aims to reduce. Tracking these trends provides clear, quantifiable evidence of whether the mitigation efforts are effectively improving the reliability and operational uptime of IT systems.

BProbability and seventy of each IT risk

Probability and severity of each IT risk are important for initial risk assessment and prioritization, but they describe the *potential* risk rather than the actual *progress* in mitigating system availability issues.

CFinancial losses and bad press releases

Financial losses and bad press releases are consequences of poor availability, but they are lagging indicators; focusing on incident severity and downtime provides more direct and actionable metrics for IT progress.

DCustomer and stakeholder complaints over time

Customer and stakeholder complaints are important feedback, but they are subjective and often lagging indicators that do not provide the direct, quantifiable operational data needed to measure specific system availability improvements.

Concept tested: Measuring IT risk mitigation effectiveness

Source: https://learn.microsoft.com/en-us/training/modules/get-started-site-reliability-engineering/6-measure-sre-success

Topics

#IT Risk Mitigation#System Availability#Performance Reporting#Key Performance Indicators

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice