QuestionQ193

Risk Assessment

Which of the following are the MOST important inputs for determining the desired state of IT risk in a gap analysis?

  • A IT risk appetite and tolerance
  • B IT risk strategy and organizational requirements
  • C IT risk and control assessment results
  • D IT vulnerability and penetration testing results
Explanation

The desired IT risk state is established from the IT risk strategy and the organization’s requirements, ensuring that risk-management objectives align with business needs, obligations, and intended outcomes. Risk and control assessments, vulnerability testing, and penetration testing principally provide evidence about the current state to compare against that target.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!