Which of the following is MOST beneficial in determining an appropriate balance between uncontrolled innovation and excessive caution in an organization?
Defining risk appetite provides clear guidance on how much risk is acceptable, helping balance innovation with caution.
It ensures that decisions around innovation and security align with the organization’s overall risk tolerance.
Why Other Options Are Less Effective:
B. Determine budget constraints: Budget constraints are important but do not address the balance between innovation and caution.
C. Review project charters: Reviewing charters provides project-specific insights but does not address organizational risk strategy.
D. Collaborate security projects: Collaboration is helpful but not as foundational as defining risk appetite.
EC-Council CISO Reference:Understanding and articulating risk appetite is a core component of governance and strategic alignment in the CISO program.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit