CISA IT Risk Management 5 — Questions and Answers
Question 1: Which of the following is the MOST effective way to ensure IT risks are aligned with business strategy?
- Conducting quarterly vulnerability scans
- Integrating IT risk management into enterprise risk management (ERM) (Correct answer)
- Requiring all employees to complete annual security awareness training
- Deploying a Security Information and Event Management (SIEM) system
Correct answer: Integrating IT risk management into enterprise risk management (ERM)
Integrating IT risk management into ERM ensures that technology risks are evaluated in the context of overall business objectives and risk appetite.
Question 2: A CISA auditor notes that management consistently accepts risks without documented justification. What is the PRIMARY concern?
- Management may be understating the organization's risk appetite
- Risk acceptance decisions lack accountability and auditability (Correct answer)
- The risk register will become too large to manage
- IT staff will not prioritize remediation efforts
Correct answer: Risk acceptance decisions lack accountability and auditability
Undocumented risk acceptance decisions cannot be audited or reviewed, undermining governance and accountability.
Question 3: What is the MAIN purpose of a Business Impact Analysis (BIA) in the context of IT risk management?
- To identify all security vulnerabilities in IT systems
- To determine the criticality of business processes and recovery priorities (Correct answer)
- To calculate the cost of implementing risk controls
- To assess the compliance posture of the organization
Correct answer: To determine the criticality of business processes and recovery priorities
A BIA identifies which business processes are most critical, helping prioritize IT risk management and recovery efforts accordingly.
Question 4: An organization implements a new cloud platform. At which stage of the IT lifecycle should risk assessment FIRST occur?
- After deployment and user acceptance testing
- During the planning and design phase (Correct answer)
- After the first security incident involving the platform
- When the first audit of the platform is scheduled
Correct answer: During the planning and design phase
Risk assessment should occur during planning and design so that controls can be built in from the start, reducing the cost and effort of remediation later.
Question 5: Which metric BEST measures the effectiveness of an IT risk management program over time?
- Number of vulnerabilities discovered per scan
- Reduction in residual risk levels across the risk register (Correct answer)
- Total IT security budget spent per year
- Number of security policies reviewed annually
Correct answer: Reduction in residual risk levels across the risk register
Tracking reductions in residual risk levels directly measures whether the risk management program is achieving its goal of lowering actual risk exposure.
Question 6: In IT risk management, what does the term 'risk aggregation' refer to?
- Combining multiple small risks to understand their cumulative effect on the organization (Correct answer)
- Splitting a large risk into smaller, manageable components
- Transferring multiple risks to a single insurance policy
- Documenting all risks in a centralized risk register
Correct answer: Combining multiple small risks to understand their cumulative effect on the organization
Risk aggregation combines individual risks to reveal their combined impact, which may be greater than any single risk in isolation.
Question 7: A CISA auditor is evaluating the IT risk management framework. Which characteristic is MOST indicative of a mature risk management process?
- Risk assessments are performed only when incidents occur
- Risk management is embedded in all IT project and change management processes (Correct answer)
- The IT department manages all risks without executive involvement
- Risk registers are maintained exclusively by the audit team
Correct answer: Risk management is embedded in all IT project and change management processes
A mature risk management process is embedded across IT operations and projects, making risk consideration a routine part of all decisions rather than a reactive exercise.
Which of the following is the MOST effective way to ensure IT risks are aligned with business strategy?