Before establishing IT key risk indicators (KRIs), it is essential to define the IT risk and security framework. The risk and security framework outlines the structure, processes, policies, and methodologies that the organization will use to identify, assess, mitigate, and manage IT risks effectively. It provides the foundational structure within which KRIs are developed and implemented.
By establishing a comprehensive risk and security framework, organizations can ensure consistency and alignment in their approach to managing IT risks. This framework helps define the scope of IT risk management activities, establish risk tolerance levels, and identify critical assets and vulnerabilities that need to be monitored through KRIs.
You need to identify the risk before implementing any KRI(s). In conclusion, the answer should be A.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ARaghunanan
2 months, 3 weeks agoshiowbah
7 months, 3 weeks agoSuperMax
8 months, 3 weeks agoGRamos
1 year, 9 months ago