Which of the following is necessary for effective risk management in IT governance?
A.
Local managers are solely responsible for risk evaluation.
B.
IT risk management is separate from corporate risk management.
C.
Risk management strategy is approved by the audit committee.
D.
Risk evaluation is embedded in management processes.
The Answer Is:
D
This question includes an explanation.
Explanation:
The necessary condition for effective risk management in IT governance is that risk evaluation is embedded in management processes. Risk evaluation is the process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. Risk evaluation should be integrated into the management processes of planning, implementing, monitoring, and reviewing the IT activities and resources. This will ensure that risk management is aligned with the business objectives, strategies, and values, and that risk responses are timely, appropriate, and effective. References:
CISA Review Manual (Digital Version)
CISA Questions, Answers & ExplanationsDatabase
CISA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"