Certified in Risk and Information Systems Control (CRISC) — Question 1102
Which of the following is MOST important for managing ethical risk?
Answer options
- A. Involving senior management in resolving ethical disputes
- B. Developing metrics to trend reported ethics violations
- C. Establishing a code of conduct for employee behavior
- D. Identifying the ethical concerns of each stakeholder
Correct answer: C
Explanation
Establishing a code of conduct for employee behavior is essential as it sets clear expectations for ethical practices within the organization. While involving senior management, developing metrics, and identifying stakeholder concerns are important, they do not provide the foundational guidelines that a code of conduct offers to navigate ethical situations effectively.