Which of the following scenarios is MOST important to communicate to senior management?
The BEST way to obtain senior management support for investment in a control implementation would be to articulate the reduction in:
A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?
From a governance perspective, which of the following is MOST important to ensure when risk management policies are being updated to facilitate the pursuit of new opportunities?
Which of the following risk activities is BEST facilitated by enterprise architecture (EA)?
For no apparent reason, the time required to complete daily processing for a legacy application is approaching a risk threshold. Which of the following activities should be performed FIRST?
Which of the following is MOST helpful in defining an early-warning threshold associated with insufficient network bandwidth’’?
The PRIMARY objective of collecting information and reviewing documentation when performing periodic risk analysis should be to:
After the implementation of a remediation plan, an assessment of associated control design and operating effectiveness can determine the level of:
An organization is considering modifying its system to enable acceptance of credit card payments. To reduce the risk of data exposure, which of the following should the organization do FIRST?
Which of the following is MOST commonly compared against the risk appetite?
Which of the following BEST confirms the existence and operating effectiveness of information systems controls?
Which of the following provides the MOST reliable evidence to support conclusions after completing an information systems controls assessment?
Which of the following roles is PRIMARILY accountable for risk associated with business information protection?
Who should be responsible for approving the cost of controls to be implemented for mitigating risk?
Which of the following is the PRIMARY purpose of creating and documenting control procedures?
Which of the following is the MOST important reason to link an effective key control indicator (KCI) to relevant key risk indicators (KRIs)?
It has been observed that a few servers are negatively impacting processing because they are running with less RAM than required by approved security standards. Who should own and drive mitigation of noncompliant platforms?
when developing IT risk scenarios associated with a new line of business, which of the following would be MOST helpful to review?
Because of a potential data breach, an organization has decided to temporarily shut down its online sales order system until sufficient controls can be implemented. Which risk treatment has been selected?
The MOST important reason for implementing change control procedures is to ensure:
Which of the following will BEST mitigate the risk associated with IT and business misalignment?
A key performance indicator (KPI) shows that a process is operating inefficiently, even though no control issues were noted during the most recent risk assessment. Which of the following should be done FIRST?
Which of the following is a PRIMARY objective of privacy impact assessments (PIAs)?
A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from being exploded?
Which of the following key performance indicators (KPis) would BEST measure me risk of a service outage when using a Software as a Service (SaaS) vendors
A risk owner has accepted a high-impact risk because the control was adversely affecting process efficiency. Before updating the risk register, it is MOST important for the risk practitioner to:
Which of the following is the BEST way to protect sensitive data from administrators within a public cloud?
A recent big data project has resulted in the creation of an application used to support important investment decisions. Which of the following should be of GREATEST concern to the risk practitioner?
An organization ' s chief information officer (CIO) has proposed investing in a new. untested technology to take advantage of being first to market Senior management has concerns about the success of the project and has set a limit for expenditures before final approval. This conditional approval indicates the organization ' s risk:
A process maturity model is MOST useful to the risk management process because it helps:
Which of the following stakeholders define risk tolerance for an enterprise?
Which of the following would require updates to an organization ' s IT risk register?
When evaluating enterprise IT risk management it is MOST important to:
Which of the following is the BEST Key control indicator KCO to monitor the effectiveness of patch management?
What would be the MAIN concern associated with a decentralized IT function maintaining multiple risk registers?
An IT department originally planned to outsource the hosting of its data center at an overseas location to reduce operational expenses. After a risk assessment, the department has decided to keep the data center in-house. How should the risk treatment response be reflected in the risk register?
Which of the following would present the GREATEST challenge when assigning accountability for control ownership?
Which of the following is MOST important to include in a Software as a Service (SaaS) vendor agreement?
An application development team has a backlog of user requirements for a new system that will process insurance claim payments for customers. Which of the following should be the MOST important consideration for a risk-based review of the user requirements?
An organization has implemented a policy requiring staff members to take a minimum of five consecutive days ' leave per year to mitigate the risk of malicious insider activities. Which of the following is the BEST key performance indicator (KPI) of the effectiveness of this policy?
Which of the following is MOST helpful to understand the consequences of an IT risk event?
Which of the following is MOST influential when management makes risk response decisions?
Which of the following is the PRIMARY benefit of using an entry in the risk register to track the aggregate risk associated with server failure?
An organization learns of a new ransomware attack affecting organizations worldwide. Which of the following should be done FIRST to reduce the likelihood of infection from the attack?
What would be MOST helpful to ensuring the effective implementation of a new cybersecurity program?
Which of the following helps ensure compliance with a nonrepudiation policy requirement for electronic transactions?
The MOST important reason to monitor key risk indicators (KRIs) is to help management:
An organization is planning to implement a Zero Trust model. From a cybersecunty perspective, which of the following is MOST important to ensure successful alignment with the overall inten Zero Trust?
Which of the following is MOST important for management to consider when deciding whether to invest in an IT initiative that exceeds management ' s risk appetite?