QuestionQ61

Risk Optimization

A CIO has just become aware of a new regulatory requirement that could affect IT-enabled business activities. Which of the following should be the CIO's FIRST step in determining the appropriate response to the new requirement?

  • A Consult with legal and risk experts to understand the requirements.
  • B Confirm there are adequate resources to mitigate compliance requirements.
  • C Consult with the board for guidance on the new requirement.
  • D Revise initiatives that are active to reflect the new requirements.
Explanation

The regulatory requirement must be interpreted and assessed for applicability, obligations, and risk before the organization can plan mitigation resources, escalate for governance guidance, or revise active initiatives. Legal and risk experts provide that foundational compliance analysis.

Community Discussion

No comments yet. Be the first to start the discussion!