Which of the following MOST enables risk-aware business decisions?
Give this one a try later!
Exchange of accurate and timely information.
Robust exchange of information enables management to optimize risk-
related decisions. Accuracy and timeliness of information are critical
success factors.
The board of directors of a one-year-old start-up company has asked the chief
information officer to create the enterprise's IT policies and procedures, which will be
managed and approved by the IT steering committee. The committee will make the IT
decisions for the enterprise, including those related to the technology budget. The IT
steering committee will be BEST represented by:
Give this one a try later!
, Key members from each department.
The IT steering committee should be comprised of individuals from each
department to ensure that the entire enterprise is represented and that all
business objectives are more likely to be met.
The aggregated results of continuous monitoring activities are BEST communicated
to:
Give this one a try later!
The risk owner.
The risk owner is the most suitable target audience for aggregated results
of continuous monitoring; the risk owner is accountable for the fact that
appropriate risk responses are executed in alignment with the enterprise's
risk appetite.
Which of the following is the MOST important information to include in a risk
management strategic plan?
Give this one a try later!
Current state and desired future state.
It is most important to paint a vision for the future and then draw a road
map from the starting point, which requires that the current state and
desired future state be fully understood.
,The marketing department procures a third-party application for global enterprise
use. During assessment of the application, it is discovered that it poses some risk to
data privacy regulations (i.e., violates or does not address data transfer and data
privacy requirements as regulated) within certain regions where the enterprise
operates. Which additional stakeholder should be included in reporting the risk?
Give this one a try later!
Chief privacy officer.
The chief privacy officer will offer support in defining controls that will be
implemented to address and mitigate the data transfer and data privacy
requirements. If the application must be used by the business, the chief
privacy officer ultimately becomes a critical stakeholder who must be
informed about the risk.
Which of the following is MOST essential for a risk management program to be
effective?
Give this one a try later!
New risk detection.
Without identifying new risk, other measures will succeed only for a limited
period.
Which of the following is the BEST method to ensure the overall effectiveness of a risk
management program?
Give this one a try later!
, Participation by applicable members of the enterprise.
Effective risk management requires the participation, support and
acceptance of all applicable members of the enterprise, beginning with
executives. Personnel must understand their responsibilities, receive
training on how to fulfill their roles, exercise active judgment, and take
appropriate action.
Who should determine the monitoring techniques for risk treatment plans?
Give this one a try later!
Risk treatment plan owner.
The risk treatment plan owner is responsible for monitoring the treatment
plan. This could be the business unit manager or control owner.
Accountability for risk ultimately belongs to the:
Give this one a try later!
Board of directors.
The board of directors of an enterprise has ultimate accountability to
shareholders, customers, employees and the general public.
Risk management strategic plans are MOST effective when developed for:
Give this one a try later!
Give this one a try later!
Exchange of accurate and timely information.
Robust exchange of information enables management to optimize risk-
related decisions. Accuracy and timeliness of information are critical
success factors.
The board of directors of a one-year-old start-up company has asked the chief
information officer to create the enterprise's IT policies and procedures, which will be
managed and approved by the IT steering committee. The committee will make the IT
decisions for the enterprise, including those related to the technology budget. The IT
steering committee will be BEST represented by:
Give this one a try later!
, Key members from each department.
The IT steering committee should be comprised of individuals from each
department to ensure that the entire enterprise is represented and that all
business objectives are more likely to be met.
The aggregated results of continuous monitoring activities are BEST communicated
to:
Give this one a try later!
The risk owner.
The risk owner is the most suitable target audience for aggregated results
of continuous monitoring; the risk owner is accountable for the fact that
appropriate risk responses are executed in alignment with the enterprise's
risk appetite.
Which of the following is the MOST important information to include in a risk
management strategic plan?
Give this one a try later!
Current state and desired future state.
It is most important to paint a vision for the future and then draw a road
map from the starting point, which requires that the current state and
desired future state be fully understood.
,The marketing department procures a third-party application for global enterprise
use. During assessment of the application, it is discovered that it poses some risk to
data privacy regulations (i.e., violates or does not address data transfer and data
privacy requirements as regulated) within certain regions where the enterprise
operates. Which additional stakeholder should be included in reporting the risk?
Give this one a try later!
Chief privacy officer.
The chief privacy officer will offer support in defining controls that will be
implemented to address and mitigate the data transfer and data privacy
requirements. If the application must be used by the business, the chief
privacy officer ultimately becomes a critical stakeholder who must be
informed about the risk.
Which of the following is MOST essential for a risk management program to be
effective?
Give this one a try later!
New risk detection.
Without identifying new risk, other measures will succeed only for a limited
period.
Which of the following is the BEST method to ensure the overall effectiveness of a risk
management program?
Give this one a try later!
, Participation by applicable members of the enterprise.
Effective risk management requires the participation, support and
acceptance of all applicable members of the enterprise, beginning with
executives. Personnel must understand their responsibilities, receive
training on how to fulfill their roles, exercise active judgment, and take
appropriate action.
Who should determine the monitoring techniques for risk treatment plans?
Give this one a try later!
Risk treatment plan owner.
The risk treatment plan owner is responsible for monitoring the treatment
plan. This could be the business unit manager or control owner.
Accountability for risk ultimately belongs to the:
Give this one a try later!
Board of directors.
The board of directors of an enterprise has ultimate accountability to
shareholders, customers, employees and the general public.
Risk management strategic plans are MOST effective when developed for:
Give this one a try later!