QuestionQ414

Risk Optimization

The CIO of a large enterprise seeks assurance that significant IT risk is proactively monitored and remains within agreed risk-tolerance levels. The BEST way to provide this continuing assurance is to require development of:

  • A key risk indicators (KRIs).
  • B an IT risk appetite statement.
  • C a risk management policy.
  • D a risk register.
Explanation

Key risk indicators (KRIs) are measurable indicators with defined thresholds that monitor risk exposure over time and provide early warning when it approaches or exceeds established tolerance levels.

Community Discussion

No comments yet. Be the first to start the discussion!