Comprehensive and Detailed Explanation:
The CGEIT Review Manual 8th Edition, in its Risk Optimization domain, underscores the CIO’s role in managing risks associated with new technology deployments. Rapid adoption of a mobile application introduces risks (e.g., security vulnerabilities, integration issues), which the CIO must prioritize to protect the enterprise. Ensuring risk is properly managed involves risk assessments, mitigation plans, and compliance checks (e.g., for data privacy). The manual likely references COBIT 2019’s APO12-Managed Risk, which emphasizes risk management for new IT initiatives.
Option A: Metrics for usage are important but secondary to risk management during implementation.
Option B: Business unit awareness is a communication task, not the CIO’s main responsibility.
Option C: EA review is relevant but less urgent than addressing immediate implementation risks.
Double Verification: The answer aligns with COBIT’s APO12 and the CGEIT domain’s focus on risk management for new technologies. Risk management is a core CIO responsibility in ISACA’s frameworks.
ISACA CGEIT Review Manual 8th Edition, Domain 4: Risk Optimization (focus on technology implementation risks).
COBIT 2019, APO12-Managed Risk.
ISACA Glossary (for definitions of risk management), available at https://www.isaca.org/resources/glossary.
Submit