QuestionQ343

Governance of Enterprise IT

An enterprise has chosen to implement an IT risk management program. After stakeholder desired outcomes have been established, the MAIN objective of the IT strategy committee should be to:

  • A perform a risk analysis on key IT processes.
  • B ensure IT risk alignment with enterprise risk.
  • C identify business data that requires protection.
  • D implement controls to address high risk areas.
Explanation

IT risk management must be aligned with enterprise risk management so that IT-related risk appetite, priorities, and treatment decisions support enterprise objectives. Performing process-level risk analysis, identifying protected data, and implementing controls are subsequent management activities used to execute that aligned strategy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!