QuestionQ189

Risk Optimization

After a major IT incident caused a loss to the enterprise, a CIO is preparing to meet with the board of directors to discuss what might have failed internally. Which of the following should the CIO do FIRST to provide assurance to the board?

  • A Review the IT control environment.
  • B Ensure IT and enterprise risk management alignment.
  • C Review the incident response policy.
  • D Verify continuous monitoring is being performed.
Explanation

The IT control environment establishes the governance, policies, procedures, accountability, and control activities used to manage IT risk. Reviewing it first provides a comprehensive basis for determining whether control weaknesses contributed to the loss and for assuring the board that those weaknesses are being identified and addressed.

Community Discussion

No comments yet. Be the first to start the discussion!