Which of the following situations provides the BEST justification for considering the adoption of a qualitative risk assessment method?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
An enterprise is considering outsourcing non-core IT processes. Which of the following should be the FIRST step?
Which of the following is the PRIMARY objective of a data protection impact assessment?
A board of directors has mandated that key performance indicators (KPIs) be developed for all IT projects that are created in support of a business objective. Which of the following MUST be reflected in the KPIs to be effective?
When developing IT risk management policies and standards, it is MOST important to align them with:
Which of the following is the GREATEST benefit of using the life cycle approach to govern information assets?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?
Which of the following is the BEST way to address the risk associated with new IT investments?
Which of the following is MOST important to ensure that IT project selections meet the enterprise’s business requirements?
A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO's NEXT course of action?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require: