An enterprise recently experienced a major breach that was escalated effectively. However, the recovery took far longer than expected, resulting in significant financial loss. Which of the following is MOST likely the root cause of this scenario?
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
Due diligence process
Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?
When reporting key risk indicators (KRIs) to the board, what information BEST enables risk-based decision-making?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?
What is the BEST way to demonstrate alignment of IT projects with long-term business objectives?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
The CIO of a financial and insurance company is considering the projects and portfolio for the coming year Which of the following projects is a non-discretionary project?
Which of the following would BEST help a CIO enhance the competencies of an IT business analytics team?
An IT risk committee is trying to mitigate the risk associated with a newly implemented bring your own device (BYOD) policy and supporting mobile device management (MDM) tools. Which of the following would be the BEST way to ensure employees understand how to protect sensitive corporate data on their mobile devices?
Which of the following would be the BEST long-term solution to address the concern regarding loss of experienced staff?
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?