nerdexam
Isaca

CRISC · Question #545

Which of the following is the PRIMARY purpose for ensuring senior management understands the organization's risk universe in relation to the IT risk management program?

The correct answer is A. To define effective enterprise IT risk appetite and tolerance levels. The primary purpose for senior management to understand the organization's risk universe is to define effective enterprise IT risk appetite and tolerance levels.

Submitted by zhang_li· Apr 18, 2026Governance

Question

Which of the following is the PRIMARY purpose for ensuring senior management understands the organization's risk universe in relation to the IT risk management program?

Options

  • ATo define effective enterprise IT risk appetite and tolerance levels
  • BTo execute the IT risk management strategy in support of business objectives
  • CTo establish business-aligned IT risk management organizational structures
  • DTo assess the capabilities and maturity of the organization's IT risk management efforts

How the community answered

(32 responses)
  • A
    75% (24)
  • B
    6% (2)
  • C
    3% (1)
  • D
    16% (5)

Why each option

The primary purpose for senior management to understand the organization's risk universe is to define effective enterprise IT risk appetite and tolerance levels.

ATo define effective enterprise IT risk appetite and tolerance levelsCorrect

Senior management's comprehensive understanding of the risk universe is essential for setting the organization's IT risk appetite (the amount of risk it is willing to take) and risk tolerance levels (the acceptable deviation from risk appetite). These strategic parameters guide all subsequent risk management activities.

BTo execute the IT risk management strategy in support of business objectives

Executing the risk management strategy is an operational function, not the primary strategic purpose for senior management's understanding of the entire risk universe; rather, their understanding enables the definition of the strategy itself.

CTo establish business-aligned IT risk management organizational structures

While senior management involvement can influence organizational structure, defining the structure is a consequence, not the primary purpose of their risk universe understanding.

DTo assess the capabilities and maturity of the organization's IT risk management efforts

Assessing maturity is an evaluation activity, which can be done by various stakeholders, but it doesn't represent the primary strategic decision-making role enabled by senior management's holistic risk understanding.

Concept tested: Senior management role in risk appetite

Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-introduction-and-methodology

Topics

#Senior Management Responsibility#Risk Appetite Definition#Risk Governance#Enterprise Risk View

Community Discussion

No community discussion yet for this question.

Full CRISC Practice