ExamGecko
Question list
Search
Search

Question 132 - CISM discussion

Report
Export

Which of the following is the BEST way to help ensure an organization's risk appetite will be considered as part of the risk treatment process?

A.
Establish key risk indicators (KRIs).
Answers
A.
Establish key risk indicators (KRIs).
B.
Use quantitative risk assessment methods.
Answers
B.
Use quantitative risk assessment methods.
C.
Provide regular reporting on risk treatment to senior management
Answers
C.
Provide regular reporting on risk treatment to senior management
D.
Require steering committee approval of risk treatment plans.
Answers
D.
Require steering committee approval of risk treatment plans.
Suggested answer: D

Explanation:

= Requiring steering committee approval of risk treatment plans is the best way to help ensure an organization's risk appetite will be considered as part of the risk treatment process because the steering committee is composed of senior management and key stakeholders who are responsible for defining and communicating the risk appetite and ensuring that it is aligned with the business objectives and strategy. The steering committee can review and approve the risk treatment plans proposed by the information security manager and ensure that they are consistent with the risk appetite and the risk tolerance levels. The steering committee can also monitor and evaluate the effectiveness of the risk treatment plans and provide feedback and guidance to the information security manager. Establishing key risk indicators (KRIs), using quantitative risk assessment methods, and providing regular reporting on risk treatment to senior management are not the best ways to help ensure an organization's risk appetite will be considered as part of the risk treatment process, although they may be useful tools and techniques to support the risk management process. KRIs are metrics that measure the level of risk exposure and the performance of risk controls. Quantitative risk assessment methods are techniques that use numerical values and probabilities to estimate the likelihood and impact of risk events. Regular reporting on risk treatment to senior management is a way to communicate the status and results of the risk treatment process and to obtain feedback and support from senior management. However, none of these methods can ensure that the risk treatment plans are approved and aligned with the risk appetite, which is the role of the steering committee.Reference= CISM Review Manual 2023, Chapter 2, Section 2.4.3, page 76; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, Question ID: 121.

asked 01/10/2024
Enayat Meer
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first