An enterprise has adopted COBIT to govern IT and wants its IT risk management to demonstrably support enterprise objectives rather than operate as a standalone technical exercise. Which approach best embeds IT risk within the enterprise risk management framework using COBIT?
- AMaintaining the IT risk register inside the security team and reporting it only to the IT director each quarter
- BCascading enterprise goals to IT-related goals and aligning risk responses to those mapped objectives Correct
- CRanking IT risks purely by the technical severity scores produced by the vulnerability scanning platform
- DOutsourcing IT risk assessment to an external firm that benchmarks the enterprise against industry peers
Why A is wrong: Keeping risk inside the security team is common practice, but siloed reporting to IT alone is exactly the standalone posture the enterprise is trying to move away from.
Why B is correct: COBIT's goals cascade traces enterprise goals to IT-related goals, so aligning risk responses to that mapping is what makes IT risk demonstrably support business objectives.
Why C is wrong: Technical severity is useful input, yet ranking on scanner scores alone ignores business impact and so fails to connect IT risk to the enterprise objectives it should serve.
Why D is wrong: External benchmarking can inform maturity, but delegating assessment outward does not build the internal goals-cascade linkage that embeds IT risk in enterprise objectives.