ExamGecko
Question list
Search
Search

Question 34 - IT Risk Fundamentals discussion

Report
Export

Which of the following is an example of a tangible and assessable representation of risk?

A.

Enterprise risk policy

Answers
A.

Enterprise risk policy

B.

Risk treatment plan

Answers
B.

Risk treatment plan

C.

Risk scenario

Answers
C.

Risk scenario

Suggested answer: C

Explanation:

A risk scenario is an example of a tangible and assessable representation of risk. Here's the breakdown:

Enterprise Risk Policy: This is a document that outlines the organization's approach to risk management. While important, it is not a specific, tangible representation of risk.

Risk Treatment Plan: This outlines the actions to mitigate identified risks. It is a strategy rather than a representation of specific risks.

Risk Scenario: This provides a detailed and concrete representation of potential risk events, their causes, and impacts. It allows for assessment and preparation, making it a tangible and assessable representation of risk.

Therefore, a risk scenario is the best example of a tangible and assessable representation of risk.

ISA 315 Anlage 5 and 6: Understanding risks, scenarios, and their impacts on IT systems and business objectives.

ISO-27001 and GoBD guidelines on risk management and identification.

These references provide a comprehensive understanding of the concepts and principles involved in IT risk and audit processes.

asked 18/11/2024
Farshin Golpad
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first