QuestionQ1760

Risk Assessment

Which of the following is a risk practitioner’s BEST recommendation for helping ensure that cyber risk is assessed and incorporated into the enterprise-level risk profile?

  • A Conduct cyber risk awareness training tailored specifically for senior management
  • B Implement a cyber risk program based on industry best practices
  • C Manage cyber risk according to the organization's risk management framework
  • D Define cyber roles and responsibilities across the organization
Explanation

Cyber risk should be managed through the organization’s risk management framework so that it uses the enterprise’s risk criteria, governance, assessment process, and reporting mechanisms. This allows cybersecurity risks to be consistently evaluated and integrated into the enterprise risk profile alongside other enterprise risks.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!