determine loss associated with specific IT assets.
C.
prioritize the enterprise's risk responses.
The Answer Is:
C
This question includes an explanation.
Explanation:
Risk impact criteria define the potential consequences of a risk event occurring. These criteria are primarily used to prioritize risk responses. By understanding the potential impact of different risks, organizations can focus their efforts on mitigating the most significant risks first.
While impact criteria can inform risk appetite (A), their primary use is in prioritization. Determining loss associated with specific IT assets (B) is part of impact assessment, but the criteria themselves are used for prioritization.
[Reference: ISACA materials on risk assessment and response, often within the Risk IT Framework and related publications, discuss the use of impact criteria for prioritization. The focus is on understanding the potential consequences to make informed decisions about risk response., ]
IT-Risk-Fundamentals PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"