QuestionQ398

Risk Optimization

After completing a gap analysis of IT risk and control capabilities, the MOST important consideration for the related risk responses is that they are:

  • A added to the IT balanced scorecard.
  • B approved by executive management.
  • C assessed for severity of impact.
  • D submitted to the audit committee.
Explanation

Risk responses require executive-management approval so that the accountable business leadership formally authorizes the chosen treatment, commits needed resources, and accepts any residual risk in line with organizational risk appetite.

Community Discussion

No comments yet. Be the first to start the discussion!