ExamGecko
Question list
Search
Search

Related questions

Question 984 - CISA discussion

Report
Export

An IS auditor is reviewing enterprise governance and finds there is no defined organizational structure for technology risk governance. Which of the following is the GREATEST concern with this lack of structure?

A.
Software developers may adopt inappropriate technology.
Answers
A.
Software developers may adopt inappropriate technology.
B.
Project managers may accept technology risks exceeding the organization's risk appetite.
Answers
B.
Project managers may accept technology risks exceeding the organization's risk appetite.
C.
Key decision-making entities for technology risk have not been identified
Answers
C.
Key decision-making entities for technology risk have not been identified
D.
There is no clear approval entity for organizational security standards.
Answers
D.
There is no clear approval entity for organizational security standards.
Suggested answer: C

Explanation:

The greatest concern with the lack of structure for technology risk governance is C. Key decision-making entities for technology risk have not been identified.Technology risk governance is the process of establishing and maintaining the policies, roles, responsibilities, and accountabilities for managing technology risks within an organization1.Technology risk governance requires a clear organizational structure that defines who has the authority and responsibility to make decisions, set objectives, allocate resources, monitor performance, and ensure compliance for technology risk management2. Without such a structure, an organization may face the following challenges:

Lack of alignment and integration between technology and business strategies, leading to suboptimal outcomes and missed opportunities.

Lack of clarity and consistency in technology risk identification, assessment, mitigation, and reporting, leading to gaps and overlaps in risk coverage and exposure.

Lack of communication and collaboration among different stakeholders involved in technology risk management, leading to conflicts and inefficiencies.

Lack of oversight and accountability for technology risk management activities and results, leading to poor quality and reliability.

asked 18/09/2024
Preety Koul
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first