Certified in Risk and Information Systems Control (CRISC) — Question 129
Which of the following would MOST likely result in updates to an IT risk appetite statement?
Answer options
- A. Changes in senior management
- B. External audit findings
- C. Feedback from focus groups
- D. Self-assessment reports
Correct answer: A
Explanation
Changes in senior management often lead to shifts in organizational priorities and risk tolerance, hence impacting the IT risk appetite statement. While external audit findings, feedback from focus groups, and self-assessment reports can provide insights, they are less likely to prompt a fundamental change in risk appetite compared to the influence of senior management.