nerdexam
PeopleCert

ITIL-4-DITS · Question #36

Which statement is CORRECT about risk management in digital organizations?

The correct answer is A. All the organization's slaveholders should contribute to risk assessment. Option A reflects the core risk management principle that risk assessment should be a collaborative, organization-wide effort - note that "slaveholders" is almost certainly a typo for "stakeholders," and the intended meaning is that everyone with a stake in the organization…

Understand how to manage strategic capabilities

Question

Which statement is CORRECT about risk management in digital organizations?

Options

  • AAll the organization's slaveholders should contribute to risk assessment
  • BAll risk management efforts should focus on assets owned by the organization
  • CAll risk management should start by assessing the current state
  • DAll risks could cause harm to the organization if they are not managed

How the community answered

(46 responses)
  • A
    78% (36)
  • B
    7% (3)
  • C
    4% (2)
  • D
    11% (5)

Explanation

Option A reflects the core risk management principle that risk assessment should be a collaborative, organization-wide effort - note that "slaveholders" is almost certainly a typo for "stakeholders," and the intended meaning is that everyone with a stake in the organization (employees, managers, partners) should contribute to identifying and evaluating risks, since no single person has visibility into all areas.

Why the distractors are wrong:

  • B is too narrow - digital organizations depend heavily on external assets like cloud services, third-party vendors, and APIs, so risk management must extend beyond internally owned assets.
  • C is not universally true - different risk frameworks (e.g., ISO 31000, NIST) begin with defining objectives or context, not necessarily a current-state assessment; there's no single mandatory starting point.
  • D is factually overstated - not all unmanaged risks cause harm; some risks may be accepted, transferred, or simply never materialize. Also, "positive risks" (opportunities) exist in risk management and don't cause harm.

Memory tip: Think of risk management as a team sport - it only works when all stakeholders play. If you see "slaveholders" on your exam, mentally replace it with "stakeholders" as this is a clear transcription error.

Topics

#risk management#stakeholder involvement#risk assessment#digital organization

Community Discussion

No community discussion yet for this question.

Full ITIL-4-DITS Practice