Isaca Certified in Risk and Information Systems Control CRISC Question # 489 Topic 49 Discussion
CRISC Exam Topic 49 Question 489 Discussion:
Question #: 489
Topic #: 49
A chief risk officer (CRO) has asked to have the IT risk register integrated into the enterprise risk management (ERM) process. Which of the following will BEST facilitate the reporting of IT risk at the enterprise level?
A.
Aggregating the IT risk scenarios into a maturity benchmark value
B.
Using an IT risk heat map to depict likelihood and impact
C.
Using the same risk taxonomy across the organization
D.
Providing a summary of open IT risk-related audit findings
Using aconsistent risk taxonomyensures that IT risks can be aggregated and compared with enterprise-level risks in a meaningful way. ISACA emphasizes that standardized risk language and categories are critical to integrating IT risk with ERM processes.
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit