nerdexam
Isaca

CRISC · Question #145

A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?

The correct answer is C. Establish IT-specific compliance objectives. To support a risk management plan for legal and regulatory scenarios, IT governance should first establish clear, IT-specific compliance objectives.

Submitted by eva_at· Apr 18, 2026Governance

Question

A highly regulated enterprise is developing a new risk management plan to specifically address legal and regulatory risk scenarios What should be done FIRST by IT governance to support this effort?

Options

  • ARequest a regulatory risk reporting methodology
  • BRequire critical success factors (CSFs) for IT risks.
  • CEstablish IT-specific compliance objectives
  • DCommunicate IT key risk indicators (KRIs) and triggers

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    7% (2)
  • C
    79% (22)
  • D
    4% (1)

Why each option

To support a risk management plan for legal and regulatory scenarios, IT governance should first establish clear, IT-specific compliance objectives.

ARequest a regulatory risk reporting methodology

Requesting a regulatory risk reporting methodology is a subsequent step after objectives are set and risks are being managed, as reporting requires clear objectives to measure against.

BRequire critical success factors (CSFs) for IT risks.

Requiring critical success factors (CSFs) for IT risks is part of setting performance goals for risk management, which comes after understanding the core compliance objectives.

CEstablish IT-specific compliance objectivesCorrect

For IT governance to effectively address legal and regulatory risk scenarios, it must first define clear, measurable IT-specific compliance objectives derived directly from the applicable laws and regulations. These objectives serve as the foundational targets and benchmarks against which IT risk management activities and controls will be aligned, ensuring that efforts are focused on meeting regulatory requirements.

DCommunicate IT key risk indicators (KRIs) and triggers

Communicating IT key risk indicators (KRIs) and triggers is an operational activity for monitoring identified risks, but the establishment of compliance objectives precedes the identification and monitoring of risks.

Concept tested: IT governance for regulatory compliance

Source: https://learn.microsoft.com/en-us/compliance/regulatory/regulatory-compliance-overview

Topics

#IT governance#Compliance objectives#Regulatory risk#Risk management plan

Community Discussion

No community discussion yet for this question.

Full CRISC Practice