QuestionQ836

Risk Response and Reporting

What is the PRIMARY objective of aggregating the impact of IT risk scenarios and documenting the results in the enterprise risk register?

  • A To ensure IT risk scenarios are consistently assessed within the organization
  • B To ensure IT risk ownership is assigned at the appropriate organizational level
  • C To ensure IT risk impact can be compared to the IT risk appetite
  • D To ensure IT risk appetite is communicated across the organization
Explanation

Aggregation and inclusion in the enterprise risk register enable IT risks with an enterprise-level effect to be owned and managed at the appropriate organizational level.

Community Discussion

No comments yet. Be the first to start the discussion!