CTO IT Governance & Risk Management 4 — Questions and Answers
Question 1: Which of the following best describes the concept of 'risk appetite' in IT governance?
- The maximum amount the company is willing to spend on cybersecurity
- The total level of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The risk remaining after controls are applied
- The probability of a risk event occurring within a fiscal year
Correct answer: The total level of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines the broad level of risk an organization is willing to tolerate in pursuit of value, distinct from risk capacity (maximum survivable risk) and residual risk.
Question 2: A CTO implements a new policy requiring quarterly IT risk reviews. Which governance principle does this MOST directly support?
- Human behavior principle
- Strategy principle
- Performance principle (Correct answer)
- Conformance principle
Correct answer: Performance principle
ISO/IEC 38500's Performance principle requires that IT supports the organization effectively and that its performance is monitored and reviewed regularly.
Question 3: When using a quantitative risk analysis approach, what does Annual Loss Expectancy (ALE) represent?
- The maximum possible loss from a single risk event
- The expected monetary loss from a risk over a one-year period (Correct answer)
- The cost of implementing controls to mitigate a risk
- The probability that a risk event will occur at least once per year
Correct answer: The expected monetary loss from a risk over a one-year period
ALE is calculated as Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing the expected yearly financial impact of a risk.
Question 4: A regulated financial technology firm must comply with both SOX and PCI DSS. Where do these frameworks MOST commonly overlap in IT governance requirements?
- Encryption key length standards
- Access controls and audit logging for sensitive systems (Correct answer)
- Business continuity plan testing frequency
- Network segmentation architecture requirements
Correct answer: Access controls and audit logging for sensitive systems
Both SOX (Section 404 IT controls) and PCI DSS require robust access controls and comprehensive audit logging for systems handling sensitive financial data.
Question 5: In IT governance, what is the role of an IT steering committee compared to an IT governance board?
- The steering committee sets policy; the governance board enforces it
- The steering committee coordinates ongoing IT initiatives at a tactical level; the governance board provides strategic oversight (Correct answer)
- They are functionally identical with different names
- The steering committee has authority over the governance board
Correct answer: The steering committee coordinates ongoing IT initiatives at a tactical level; the governance board provides strategic oversight
IT steering committees typically operate at a management/tactical level coordinating projects and resources, while governance boards provide strategic direction and board-level oversight.
Question 6: Which risk response is being used when an organization decides to discontinue a business process that introduces unacceptable cybersecurity risk?
- Risk transfer
- Risk mitigation
- Risk acceptance
- Risk avoidance (Correct answer)
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by not engaging in the activity or business process that creates the risk exposure.
Question 7: A CTO wants to establish an IT governance maturity model baseline. Which tool is MOST appropriate for measuring IT governance capability maturity?
- COBIT Performance Management (CPM) (Correct answer)
- NIST Cybersecurity Framework Tiers
- ITIL Maturity Model
- ISO 31000 Risk Maturity Assessment
Correct answer: COBIT Performance Management (CPM)
COBIT Performance Management (formerly the Process Capability Model based on ISO/IEC 15504) is specifically designed to measure and benchmark IT governance and management process maturity.
Which of the following best describes the concept of 'risk appetite' in IT governance?