Which of the following is the FIRST step when developing an IT risk management framework?
A.
Promoting a culture of risk awareness
B.
Establishing a risk control library
C.
Aligning to enterprise risk management (ERM)
D.
Establishing risk appetite
The Answer Is:
C
This question includes an explanation.
Explanation:
Developing an IT risk management framework begins with aligning it to the enterprise risk management (ERM) framework. This ensures consistency across all organizational risk domains and supports the integration of IT risk into the broader enterprise risk strategy. The ERM provides a foundation for identifying, assessing, and managing IT risks in a way that aligns with the organization's overall objectives. Promoting a culture of risk awareness, while critical, is a subsequent step once the framework is defined. References: COBIT 2019 Risk Management Process, CGEIT Exam Manual.
CGEIT PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"