Q: 18
The board of an organization has been informed of possible cyberthreats. Which of the following
should be the board’s NEXT course of action?
Options
Discussion
D . The board shouldn't jump right into evaluating controls or reassessing risk tolerance without first having a proper assessment of the actual risk at hand. It's not their job to do the analysis themselves, but to delegate that to the CIO or equivalent so they get an informed picture before making any policy or appetite decisions. If there was already a confirmed incident, A might be closer, but here it's just potential threats. Anyone disagree?
Option D here. The board's role is oversight, not hands-on analysis, so they should have the CIO do the risk evaluation first. Pretty sure that's what ISACA wants in this kind of scenario.
A is wrong, D. The board should delegate risk evaluation to the CIO at this stage.
Call it D. Had something like this in a mock exam, always about the board directing the CIO to assess risk first.
Man, ISACA loves the vision statement questions. A imo, always pops up in these practice sets.
Be respectful. No spam.
Question 18 of 35