nerdexam
PeopleCert

ITIL-FOUNDATION · Question #347

Which of the following should NOT be a concern of Risk Management?

The correct answer is D. To ensure only the change requests with mitigated risks are approved for implementation. Gatekeeping change approvals based on risk mitigation is the responsibility of Change Management, not Risk Management, making option D the item that does NOT belong.

Know the purpose of the ITIL practices

Question

Which of the following should NOT be a concern of Risk Management?

Options

  • ATo ensure that the organization can continue to operate in the event of a major disruption or
  • BTo ensure that the workplace is a safe environment for its employees and customers
  • CTo ensure that the organization assets, such as information, facilities and building are protected
  • DTo ensure only the change requests with mitigated risks are approved for implementation

How the community answered

(29 responses)
  • A
    17% (5)
  • B
    3% (1)
  • C
    7% (2)
  • D
    72% (21)

Why each option

Gatekeeping change approvals based on risk mitigation is the responsibility of Change Management, not Risk Management, making option D the item that does NOT belong.

ATo ensure that the organization can continue to operate in the event of a major disruption or

Ensuring the organization can continue operating during major disruptions is a core Risk Management concern, directly tied to business continuity and resilience planning.

BTo ensure that the workplace is a safe environment for its employees and customers

Workplace safety for employees and customers is a recognized domain of Risk Management, covering health and safety risks.

CTo ensure that the organization assets, such as information, facilities and building are protected

Protecting organizational assets such as information, facilities, and buildings is a fundamental Risk Management responsibility aligned with asset and information security risk.

DTo ensure only the change requests with mitigated risks are approved for implementationCorrect

Risk Management identifies, assesses, monitors, and controls risks at an organizational level - it does not own or gate the change approval process. The Change Advisory Board (CAB) within Change Management is responsible for evaluating and approving change requests based on risk assessment outcomes produced by Risk Management.

Concept tested: Scope and boundaries of ITIL Risk Management

Source: https://www.axelos.com/certifications/itil-service-management/what-is-itil

Topics

#risk management#change management#risk scope#organizational risk

Community Discussion

No community discussion yet for this question.

Full ITIL-FOUNDATION Practice