ExamGecko
Question list
Search
Search

Related questions











Question 491 - CISA discussion

Report
Export

Which of the following provides the MOST useful information regarding an organization's risk appetite and tolerance?

A.
Gap analysis
Answers
A.
Gap analysis
B.
Audit reports
Answers
B.
Audit reports
C.
Risk profile
Answers
C.
Risk profile
D.
Risk register
Answers
D.
Risk register
Suggested answer: C

Explanation:

The most useful information regarding an organization's risk appetite and tolerance is provided by its risk profile, as this is a document that summarizes the key risks that the organization faces, the potential impacts and likelihoods of those risks, and the acceptable levels of risk exposure for different objectives and activities. A gap analysis is a tool that compares the current state and the desired state of a process or a system, and identifies the gaps that need to be addressed. Audit reports are documents that present the findings, conclusions, and recommendations of an audit engagement.A risk register is a tool that records and tracks the identified risks, their causes, their consequences, and their mitigation actions.Reference:CISA Review Manual (Digital Version), Chapter 2: Governance and Management of IT, Section 2.1: IT Governance

asked 18/09/2024
Jailson Batista
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first