ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 570 - CGEIT discussion

Report
Export

Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?

A.

Treat as a risk to be assessed before developing a response.

Answers
A.

Treat as a risk to be assessed before developing a response.

B.

Benchmark how other IT organizations are treating the new requirements.

Answers
B.

Benchmark how other IT organizations are treating the new requirements.

C.

Adopt a zero-tolerance approach for noncompliance with regulatory matters.

Answers
C.

Adopt a zero-tolerance approach for noncompliance with regulatory matters.

D.

Use a cost-benefit analysis to determine if compliance is warranted.

Answers
D.

Use a cost-benefit analysis to determine if compliance is warranted.

Suggested answer: A

Explanation:

The best way for an enterprise to address new legal and regulatory requirements applicable to IT is to treat them as a risk to be assessed before developing a response. This approach involves identifying the potential impact of the new requirements on the organization, evaluating the likelihood and consequences of non-compliance, and then developing a prioritized response plan based on this risk assessment. This method ensures a measured and proportional response that aligns with the organization's risk appetite and strategic objectives. While benchmarking, adopting a zero-tolerance approach, and using cost-benefit analysis are useful, they should be part of a broader risk-based strategy to address compliance effectively.

asked 18/11/2024
Hristo Slaveev
25 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first