IT risk is a subset of enterprise risk. Integration ensures IT risks arevisible and prioritizedalongside strategic and operational risks.
CRISC framework explains:
“Integration of IT risk management with ERM ensures that technology-related risks are appropriately represented in the overall corporate risk profile and reporting structure.”
Hence,Dis correct.
CRISC Reference:Domain 1 – IT Risk Governance, Topic: Enterprise and IT Risk Integration.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit