QuestionQ114

Risk Response and Reporting

What is the MAIN reason for continuously monitoring IT-related risk?

  • A To ensure risk levels are within acceptable limits of the organization's risk appetite and risk tolerance
  • B To redefine the risk appetite and risk tolerance levels based on changes in risk factors
  • C To help identify root causes of incidents and recommend suitable long-term solutions
  • D To update the risk register to reflect changes in levels of identified and new IT-related risk
Explanation

Continuous monitoring provides timely visibility of IT-related risk exposure so it can be managed within the organization’s established risk appetite and risk tolerance. COBIT’s risk-governance objective is to ensure IT-related enterprise risk does not exceed those limits.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!