Which of the following should be the PRIMARY objective of promoting a risk-aware culture within an organization?
Correct Answer: A
Section: Volume D
Question 162
Which of the following processes is described in the statement below? "It is the process of exchanging information and views about risks among stakeholders, such as groups, individuals, and institutions."
Correct Answer: D,E
is incorrect. A risk response ensures that the residual risk is within the limits of the risk appetite and tolerance of the enterprise. Risk response is process of selecting the correct, prioritized response to risk, based on the level of risk, the enterprise's risk tolerance and the cost and benefit of the particular risk response option. Risk response ensures that management is providing accurate reports on: The level of risk faced by the enterprise The incidents' type that have occurred Any alteration in the enterprise's risk profile based on changes in the risk environment
Question 163
Which of the following is the MOST important consideration when sharing risk management updates with executive management?
Correct Answer: C
Question 164
Which of the following is NOT true for risk governance?
Correct Answer: B
Explanation/Reference: Explanation: Risk governance is a continuous life cycle that requires regular reporting and ongoing review, not once a year. Incorrect Answers: A, C, D: These are true for risk governance.
Question 165
Which of the following is the MAIN reason for documenting the performance of controls?