CGEIT Certified in the Governance of Enterprise IT – Question047

Which of the following is MOST critical to have in place before management can establish an IT risk assessment and response approach?

A.
A portfolio of IT investments
B. Defined roles and responsibilities
C. Historic data on risk events
D. A balanced scorecard

Correct Answer: B