A recently purchased IT application does not meet project requirements. Of the following, who is accountable for the potential impact?
A risk practitioner is collaborating with key stakeholders to prioritize a large number of IT risk scenarios. Which scenarios should receive the PRIMARY focus?
An organization's business gap analysis reveals the need for a robust IT risk strategy. Which of the following should be the risk practitioner's PRIMARY consideration when participating in development of the new strategy?
Which of the following is the MOST important reason to create risk scenarios?
The operational risk associated with attacks on a web application should be owned by the individual in charge of:
During the internal review of an accounts payable process, a risk practitioner determines that the transaction approval limits configured in the system are not being enforced. Which of the following should be done NEXT?
Business areas within an organization have engaged various cloud service providers directly without assistance from the IT department. What should the risk practitioner do?
Which of the following provides the MOST important information to facilitate a risk response decision?
What should be the PRIMARY driver for periodically reviewing and adjusting key risk indicators (KRIs)?
Which key performance efficiency IKPI) BEST measures the effectiveness of an organization's disaster recovery program?
Which of the following is the BEST criterion to determine whether higher residual risk ratings in the risk register should be accepted?
Numerous media reports indicate a recently discovered technical vulnerability is being actively exploited. Which of the following would be the BEST response to this scenario?
During an organization's simulated phishing email campaign, which of the following is the BEST indicator of a mature security awareness program?
When an organization's business continuity plan (BCP) states that it cannot afford to lose more than three hours of a critical application's data, the three hours is considered the application’s:
An organization has asked an IT risk practitioner to conduct an operational risk assessment on an initiative to outsource the organization's customer service operations overseas. Which of the following would MOST significantly impact management's decision?
Controls should be defined during the design phase of system development because:
A monthly payment report is generated from the enterprise resource planning (ERP) software to validate data against the old and new payroll systems. What is the BEST way to mitigate the risk associated with data integrity loss in the new payroll system after data migration?