Certified in Risk and Information Systems Control (CRISC) — Question 1102

Which of the following is MOST important for managing ethical risk?

Answer options

Correct answer: C

Explanation

Establishing a code of conduct for employee behavior is essential as it sets clear expectations for ethical practices within the organization. While involving senior management, developing metrics, and identifying stakeholder concerns are important, they do not provide the foundational guidelines that a code of conduct offers to navigate ethical situations effectively.