nerdexam
PeopleCert

ITIL · Question #347

Which of the following should NOT be a concern of Risk Management?

The correct answer is D. To ensure only the change requests with mitigated risks are approved for implementation. Risk Management is a broad organizational discipline, but gating change approvals based solely on mitigated risks is a responsibility of Change Management, not Risk Management.

Processes

Question

Which of the following should NOT be a concern of Risk Management?

Options

  • ATo ensure that the organization can continue to operate in the event of a major disruption or
  • BTo ensure that the workplace is a safe environment for its employees and customers
  • CTo ensure that the organization assets, such as information, facilities and building are protected
  • DTo ensure only the change requests with mitigated risks are approved for implementation

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    12% (6)
  • D
    80% (41)

Why each option

Risk Management is a broad organizational discipline, but gating change approvals based solely on mitigated risks is a responsibility of Change Management, not Risk Management.

ATo ensure that the organization can continue to operate in the event of a major disruption or

Ensuring the organization can continue to operate after a major disruption is a core concern of Risk Management, specifically through Business Continuity Planning which is risk-driven.

BTo ensure that the workplace is a safe environment for its employees and customers

Workplace health and safety is a recognized domain of organizational risk management, as harm to employees or customers represents a direct operational and reputational risk.

CTo ensure that the organization assets, such as information, facilities and building are protected

Protecting organizational assets such as information, facilities, and buildings is a fundamental objective of Risk Management, aligned with information security and physical security risk practices.

DTo ensure only the change requests with mitigated risks are approved for implementationCorrect

Change Management, not Risk Management, is responsible for evaluating and approving change requests - including assessing associated risks. Risk Management identifies, assesses, and recommends responses to risks at an organizational level but does not directly control the change approval workflow or mandate that only changes with fully mitigated risks are approved.

Concept tested: Scope and boundaries of Risk Management vs Change Management

Source: https://www.axelos.com/best-practice-solutions/itil/what-is-itil

Topics

#Risk Management#Change Management#Risk scope

Community Discussion

No community discussion yet for this question.

Full ITIL Practice