ITIL-4-DITS · Question #22
Which should be included in the 'risk management' practice for a digital organization? 1. Developing a target architecture based on risk. 2. Ensuring actions are taken to reduce all risks. 3…
The correct answer is C. 3 and 4. Options 3 and 4 are correct because effective risk management practice requires both a cultural foundation - where people across the organization are aware of and engaged with risk - and a governance structure that defines accountability, oversight, and decision-making…
Question
Options
- A1 and 2
- B2 and 3
- C3 and 4
- D1 and 4
How the community answered
(47 responses)- A13% (6)
- B6% (3)
- C79% (37)
- D2% (1)
Explanation
Options 3 and 4 are correct because effective risk management practice requires both a cultural foundation - where people across the organization are aware of and engaged with risk - and a governance structure that defines accountability, oversight, and decision-making authority around risk. These are the two pillars that make risk management sustainable and organization-wide.
Option 1 is wrong because developing a target architecture based on risk belongs to the architecture management practice, not risk management - it's a design/planning concern, not a risk management responsibility.
Option 2 is wrong because risk management does not aim to eliminate all risks - that's neither possible nor desirable. Risks can also be accepted, transferred, or tolerated; the goal is informed decision-making, not zero risk.
Memory tip: Think "Culture + Governance = Core risk management" - the two soft pillars (people mindset and structural oversight) are what the risk management practice owns. Anything that sounds like a technical output (architecture) or an absolute guarantee (reduce all risks) is a red flag distractor.
Topics
Community Discussion
No community discussion yet for this question.