IT リスク管理プラクティスを企業全体の運用リスク管理フレームワークに統合する最も重要な理由は次のうちどれですか?
正解:D
Integration of IT risk management into enterprise-wide risk management ensures that IT-related risks are not treated in isolation but are included in the overall corporate risk profile, reflecting their true impact on strategic and operational objectives. According to the CRISC manual and ISACA's Risk IT Framework: * IT risk is a subset of enterprise risk and must be managed as part of the overall operational risk context. * Integrating IT risk management ensures risk aggregation and visibility at the enterprise level, allowing accurate reporting to senior management and the board. Supporting extract (CRISC Slide 32-33): "The most important aspect for an effective IT risk management process is aligning with enterprise risk management. The primary goal of an enterprise's IT risk management process is to protect the enterprise and its ability to perform its mission." This integration allows: * Inclusion of IT risk scenarios (e.g., data breaches, system outages) in overall enterprise risk assessments. * Unified reporting to management for strategic decisions. * A common language and tolerance level for all risk types. Hence, D. To ensure IT risk scenarios are reflected in the corporate risk profile is the correct answer.