QuestionQ247

Risk Optimization

Which of the following is MOST critical to establish before management can create an IT risk assessment and response approach?

  • A A portfolio of IT investments
  • B Defined roles and responsibilities
  • C Historic data on risk events
  • D A balanced scorecard
Explanation

Defined roles and responsibilities establish who owns risks, performs assessments, approves or accepts risk, implements treatment actions, and monitors results. This accountability is necessary for a risk assessment and response approach to operate. ISACA notes that roles and responsibilities should be clearly defined so stakeholders understand what is expected during a risk assessment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!