CRISC Certified in Risk and Information Systems ControlGovernanceHard
A non-profit organization relies heavily on donations and public trust. A recent data breach involving donor information has severely damaged its reputation and fundraising efforts. The board of directors is now demanding immediate improvements in risk management. To address this, the newly appointed CRO proposes implementing a comprehensive enterprise risk management (ERM) framework. Which of the following is the MOST critical initial step for the CRO to take to ensure the ERM framework effectively restores trust and prevents future breaches?
- ADevelop a new set of data security policies and procedures.
- BEstablish clear risk appetite and tolerance levels with the board and senior management.
- CInvest in advanced cybersecurity technologies to protect donor information.
- DConduct a thorough risk assessment to identify all potential threats to donor data.
Show answer & explanationAnswer & explanation
Correct answer: B. Establish clear risk appetite and tolerance levels with the board and senior management.
Establishing clear risk appetite and tolerance levels with the board and senior management is the MOST critical initial step. Without a defined risk appetite, subsequent risk assessments, policy development, or technology investments may not align with the organization's strategic objectives or the board's expectations for trust and breach prevention. It provides the foundation for all other ERM activities.
Why the other options are wrong
- A. Policies and procedures are important components of risk treatment, but they should be developed after understanding the organization's risk appetite and the results of a comprehensive risk assessment.
- C. Technology investment is a risk treatment measure; without understanding the organization's risk appetite, such investments might be misdirected or insufficient to meet the overall risk strategy.
- D. While a thorough risk assessment is essential, it must be guided by the organization's risk appetite to prioritize effectively and ensure alignment with strategic goals.
Risk Appetite Definition
The amount and type of risk that an organization is willing to pursue or retain in the pursuit of its strategic objectives.
- Set by the board and senior management.
- Guides decision-making across all levels of the organization.
- Forms the foundation for effective enterprise risk management.
Memory trick: Appetite First, Then the Rest, Build on Trust.