NEW
Font size
WorksheetsModule D4.1: Risk Strategy
Total questions: 10
Worksheet time: 5mins
What is the primary purpose of a risk framework?
To eliminate all risks in an organisation
To provide structured guidelines for marketing activities
To systematically identify, assess, manage, and monitor risks
To replace corporate governance policies
Which of the following is a characteristic of an effective risk framework?
It eliminates the need for risk reporting
It promotes a proactive risk culture
It applies only to financial departments
It guarantees risk-free operations
Which risk framework is most commonly used in IT and cybersecurity?
ISO 31000 Framework
NIST Risk Management Framework
COSO ERM Framework
Basel III Accord
What does the COSO ERM Framework primarily focus on?
Operational resilience
Securing information systems
Integrating enterprise risk management with strategy and performance
Self-directed vulnerability evaluation
Risk standards are primarily designed to:
Eliminate compliance reporting
Provide universally accepted guidelines for risk management
Replace risk frameworks
Increase organisational risk exposure
Which of the following is a global standard for risk management principles?
ISO 31000:2018
OCTAVE
COBIT 2019
Solvency II Directive
Which risk standard specifically addresses information security risk management?
Basel III Accord
ISO/IEC 27005
ISO 22301
COSO ERM
Enterprise Risk Management (ERM) differs from traditional risk management because it:
Focuses only on financial risks
Considers risks in isolation
Considers interdependencies of various risks across the organisation
Ignores reputational risks
Risk appetite is best described as:
The measurable threshold of downtime an organisation can accept
The high-level amount and type of risk an organisation is willing to pursue or retain
A method for auditing financial statements
A risk framework used for IT governance
Risk tolerance is:
The same as risk appetite
A qualitative statement of organisational vision
The specific threshold of risk exposure acceptable at an operational or project level
An international standard for risk management
