CAF-3 · Chapter 16 · Question 11 of 15
Before designing or purchasing any new IT controls, the Chief Information Security Officer (CISO) conducts a thorough review to identify the organization's most critical data assets and their specific vulnerabilities. Which step of the ITGC implementation process is this?
Test yourself: pick an answer
Reveal answer & explanation
Correct answer: B) Risk Assessment
Explanation
The first step in implementing ITGCs is Risk Assessment, where an organization identifies its critical assets, evaluates potential threats, and determines the vulnerabilities that need to be addressed
More The 5 Key Components of ITGCs (Application Scenarios) MCQs
- Q13A global retail brand struggles to maintain a unified ITGC framework because its European branches must follow GDPR privacy laws, while…
- Q14An organization implements such strict and complex IT General Controls that employees find it difficult to complete basic daily tasks…
- Q15Why must an organization's ITGC framework continuously evolve rather than remaining static after its initial implementation?
- Q1A financial controller sets a rule in the accounting software that no invoice above Rs. 500,000 can be processed without two managerial…
- Q2What is the fundamental, overarching objective of implementing IT General Controls (ITGCs) within an organization?
