Committee minutes should evidence what was decided, which exposures were accepted and which actions were assigned to whom. Attendance and topics discussed show a meeting happened, not that risk was governed.
Question 2 of 10 · IT Risk Assessment
Which is the principal purpose of documenting assumptions?
Documented assumptions let others challenge a conclusion and let it be revisited when an assumption changes. Satisfying audit is a by-product; the value is keeping the assessment honest over time.
Question 3 of 10 · Risk Response and Reporting
Which best describes a control owner's responsibility?
The control owner operates the control and keeps evidence it works. Accepting residual risk and choosing the treatment belong to the risk owner, and board reporting to management.
Question 4 of 10 · Information Technology and Security
Which factor most determines whether encryption provides real protection?
Encryption protects data only as well as the keys are controlled and as far as decryption happens away from the attacker. Key length and algorithm matter little if the wrong party holds the keys or data is decrypted where it is exposed.
Question 5 of 10 · Governance
What should determine the risk management framework's design?
The framework should fit the organisation: its size, complexity, obligations and how decisions are really made. Copying a standard or a peer wholesale produces a framework people work around.
Question 6 of 10 · IT Risk Assessment
What does target risk represent?
Target risk is the level the organisation intends to reach once the planned treatment is delivered. Residual risk is where it stands after current controls; appetite is the limit it will tolerate.
Question 7 of 10 · Risk Response and Reporting
Which describes the correct relationship between control owner and risk owner?
The control owner operates the control and evidences it; the risk owner is accountable for the exposure and accepts what remains. Merging the roles removes the check between them.
Question 8 of 10 · Information Technology and Security
Which describes the shared responsibility model in cloud services?
Under shared responsibility, the provider secures the platform and the customer secures its own data, identities and configuration; the split shifts with the service model. Accountability for the customer's data never moves to the provider.
Question 9 of 10 · Governance
What is the audit and risk functions' correct relationship?
Risk and audit coordinate planning and share information to avoid gaps and duplication, while audit keeps its independence to give assurance over the risk function too. Joint ownership or reporting lines would compromise that.
Question 10 of 10 · IT Risk Assessment
Which factor should determine the depth of a risk assessment?
How deep to go depends on how material the decision the assessment supports is. A major investment warrants detail; a small reversible choice does not.
0 of 10
Governance
IT Risk Assessment
Risk Response and Reporting
Information Technology and Security
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.