CRISC - Governance - Section 1.7

Apply enterprise risk management concepts and a risk management framework to govern IT risk.

Apply enterprise risk management concepts from frameworks such as COSO ERM and COBIT to govern IT risk as part of the broader organisational risk universe. Distinguish between the roles each framework plays and select the elements appropriate to the organisation's maturity and context.

Enterprise risk managementRisk management frameworkCOSO ERMCOBIT

Practice question for this objective

Free sampleGovernancehard

An enterprise has adopted COBIT to govern IT and wants its IT risk management to demonstrably support enterprise objectives rather than operate as a standalone technical exercise. Which approach best embeds IT risk within the enterprise risk management framework using COBIT?

  • AMaintaining the IT risk register inside the security team and reporting it only to the IT director each quarter
  • BCascading enterprise goals to IT-related goals and aligning risk responses to those mapped objectives Correct
  • CRanking IT risks purely by the technical severity scores produced by the vulnerability scanning platform
  • DOutsourcing IT risk assessment to an external firm that benchmarks the enterprise against industry peers
Using COBIT's goals cascade to link enterprise goals to IT goals lets risk responses be aligned to business objectives rather than treated as standalone technical work. COBIT provides a goals cascade that derives IT-related goals from enterprise goals; aligning risk identification and response to that chain ensures IT risk decisions are justified by their effect on business objectives, which is what embedding IT risk in the enterprise framework requires.

Why A is wrong: Keeping risk inside the security team is common practice, but siloed reporting to IT alone is exactly the standalone posture the enterprise is trying to move away from.

Why B is correct: COBIT's goals cascade traces enterprise goals to IT-related goals, so aligning risk responses to that mapping is what makes IT risk demonstrably support business objectives.

Why C is wrong: Technical severity is useful input, yet ranking on scanner scores alone ignores business impact and so fails to connect IT risk to the enterprise objectives it should serve.

Why D is wrong: External benchmarking can inform maturity, but delegating assessment outward does not build the internal goals-cascade linkage that embeds IT risk in enterprise objectives.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.