CRISC Certified in Risk and Information Systems ControlGovernanceMedium

A Chief Information Officer (CIO) is preparing to present the annual IT risk posture to the board of directors. The board has expressed a desire to understand not just the technical risks, but also their potential impact on strategic objectives and the organization's reputation. Which approach should the CIO take to BEST align the risk report with the board's expectations?

  1. ATranslating technical risks into business impact scenarios, linking them to strategic objectives and reputational harm.
  2. BPresenting a detailed breakdown of technical vulnerabilities and patches applied.
  3. CFocusing on the financial cost of potential cyber incidents and recovery efforts.
  4. DComparing the organization's IT risk metrics against industry benchmarks.
Show answer & explanation

Correct answer: A. Translating technical risks into business impact scenarios, linking them to strategic objectives and reputational harm.

Boards are primarily concerned with strategic and business-level impacts. Translating technical risks into relatable business scenarios, including effects on strategic objectives and reputation, effectively communicates the 'so what' of IT risks in terms the board understands.

Why the other options are wrong

  • B. This is too technical for most board members and does not address the impact on strategic objectives or reputation, which are their key concerns.
  • C. While financial cost is part of business impact, focusing solely on it overlooks other critical strategic and reputational dimensions the board is interested in.
  • D. Benchmarking provides context but doesn't explain the specific impact of risks on the organization's unique strategic objectives or reputation, which is the board's primary interest.

Strategic Risk Reporting for Boards

The practice of presenting risk information to the board of directors by translating technical or operational risks into their potential impact on the organization's strategic objectives, financial performance, and reputation.

  • Aligns IT risk with business strategy.
  • Enables informed strategic decision-making.
  • Communicates 'so what' of risks to non-technical leadership.

Memory trick: Speak the board's language: impacts on strategy and fame.

More Governance questions