ExamGecko
Question list
Search
Search

Related questions











Question 339 - CISA discussion

Report
Export

Which of the following is necessary for effective risk management in IT governance?

A.
Local managers are solely responsible for risk evaluation.
Answers
A.
Local managers are solely responsible for risk evaluation.
B.
IT risk management is separate from corporate risk management.
Answers
B.
IT risk management is separate from corporate risk management.
C.
Risk management strategy is approved by the audit committee.
Answers
C.
Risk management strategy is approved by the audit committee.
D.
Risk evaluation is embedded in management processes.
Answers
D.
Risk evaluation is embedded in management processes.
Suggested answer: D

Explanation:

The necessary condition for effective risk management in IT governance is that risk evaluation is embedded in management processes. Risk evaluation is the process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. Risk evaluation should be integrated into the management processes of planning, implementing, monitoring, and reviewing the IT activities and resources. This will ensure that risk management is aligned with the business objectives, strategies, and values, and that risk responses are timely, appropriate, and effective.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Claudia Arrais
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first