CISM Certified Information Security Manager – Question0625

In an organization with effective IT risk management, the PRIMARY reason to establish key risk indicators (KRIs) is to:

A.
provide information to remediate risk events.
B. demonstrate the alignment of risk management efforts.
C. map potential risk to key organizational strategic initiatives.
D. identity triggers that exceed risk thresholds.

Correct Answer: C