組織の最高情報責任者 (CIO) は、市場に最初に参入することの利点を生かすために、新しい未検証のテクノロジへの投資を提案しました。上級管理職はプロジェクトの成功を懸念しており、最終承認前に支出の制限を設定しました。この条件付き承認は、組織のリスクを示しています。
正解:B
The conditional approval of the CIO's proposal indicates the organization's risk appetite. Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives. By setting a limit for expenditures before final approval, senior management is expressing their willingness to take a calculated risk with the new technology, but also their desire to control the potential loss or harm. Risk capacity, management capability, and treatment strategy are other possible factors, but they are not as relevant as risk appetite. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 8; CRISC Review Manual, 6th Edition, page 97