โ† All CISA Flashcard Decks

IT Risk Management Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Risk Management flashcards as text
  1. Which of the following is the MOST effective way to ensure IT risks are aligned with business strategy?

    Answer: Integrating IT risk management into enterprise risk management (ERM)

    Integrating IT risk management into ERM ensures that technology risks are evaluated in the context of overall business objectives and risk appetite.

  2. A CISA auditor notes that management consistently accepts risks without documented justification. What is the PRIMARY concern?

    Answer: Risk acceptance decisions lack accountability and auditability

    Undocumented risk acceptance decisions cannot be audited or reviewed, undermining governance and accountability.

  3. What is the MAIN purpose of a Business Impact Analysis (BIA) in the context of IT risk management?

    Answer: To determine the criticality of business processes and recovery priorities

    A BIA identifies which business processes are most critical, helping prioritize IT risk management and recovery efforts accordingly.

  4. An organization implements a new cloud platform. At which stage of the IT lifecycle should risk assessment FIRST occur?

    Answer: During the planning and design phase

    Risk assessment should occur during planning and design so that controls can be built in from the start, reducing the cost and effort of remediation later.

  5. Which metric BEST measures the effectiveness of an IT risk management program over time?

    Answer: Reduction in residual risk levels across the risk register

    Tracking reductions in residual risk levels directly measures whether the risk management program is achieving its goal of lowering actual risk exposure.

  6. In IT risk management, what does the term 'risk aggregation' refer to?

    Answer: Combining multiple small risks to understand their cumulative effect on the organization

    Risk aggregation combines individual risks to reveal their combined impact, which may be greater than any single risk in isolation.

  7. A CISA auditor is evaluating the IT risk management framework. Which characteristic is MOST indicative of a mature risk management process?

    Answer: Risk management is embedded in all IT project and change management processes

    A mature risk management process is embedded across IT operations and projects, making risk consideration a routine part of all decisions rather than a reactive exercise.