QuestionQ639

Governance

Which of the following is the MOST important responsibility of an IT risk committee that oversees IT risk management?

  • A Conduct regular surveys to assess organizational risk awareness
  • B Implement an industry-recognized IT risk management framework
  • C Ensure significant risk scenarios are elevated to the board
  • D Develop and communicate an IT risk RACI chart.
Explanation

IT risk governance requires material risk information to reach the board, which is accountable for oversight of enterprise IT governance and major IT matters. Risk-awareness surveys, framework implementation, and RACI development are management-level activities that can support the program but do not replace escalation of significant risk scenarios for board oversight.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!