An enterprise is piloting Internet of Things sensors across its factory floor and plans a wider rollout. The risk practitioner is asked how to keep the related IT risk visible to decision makers as adoption grows. Which action BEST supports ongoing risk oversight?
- ARecord the pilot risks once in the project file and close them when the pilot ends, since the wider rollout is a separate later initiative.
- BDelegate all sensor risk decisions to the vendor under the support contract, as the vendor understands the devices better than internal staff.
- CAdd the emerging technology exposures to the enterprise risk register and report them to governance as the deployment scales and changes. Correct
- DWait until a sensor security incident occurs and then brief governance, because that is the point at which the exposure becomes a confirmed reality.
Why A is wrong: Closing the risks at pilot end feels tidy, but the exposures persist and scale with the rollout, so a one-off record leaves later decisions uninformed.
Why B is wrong: Vendor expertise is useful, yet delegating the decisions transfers neither accountability nor the enterprise's obligation to manage risk within its own appetite.
Why C is correct: Recording the exposures in the risk register and reporting them as the deployment grows keeps decision makers informed and supports ongoing, risk-based oversight.
Why D is wrong: Briefing only after an incident is purely reactive and denies decision makers the chance to act on the exposure before it is exploited.