QuestionQ414
Risk OptimizationThe CIO of a large enterprise seeks assurance that significant IT risk is proactively monitored and remains within agreed risk-tolerance levels. The BEST way to provide this continuing assurance is to require development of:
- A key risk indicators (KRIs).
- B an IT risk appetite statement.
- C a risk management policy.
- D a risk register.
Community Discussion