Which term describes the set of activities and framework for directing and controlling risk across the organization?

Prepare for the ISACA IT Risk Fundamentals Test. Find flashcards and multiple choice questions, complete with hints and explanations. Ace your exam with confidence!

Multiple Choice

Which term describes the set of activities and framework for directing and controlling risk across the organization?

Risk governance is the framework and set of activities that steer how risk is approached and controlled across the organization. It includes establishing policy, defining roles and responsibilities, setting risk appetite, ensuring alignment with objectives, and providing ongoing oversight and assurance through monitoring and reporting. This umbrella structure ensures risk-related decisions are made consistently and escalated appropriately, with information flowing to senior management and the board.

An asset is something of value to protect; a stakeholder is any party with an interest in the organization; a risk universe is the catalog of risk categories used for assessment. None of these describe the overarching framework for directing and controlling risk across the whole organization the way risk governance does.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy