An IS auditor is evaluating an organization's IT risk management process. The auditor finds that risk assessments are performed annually by the IT department alone, without input from business units. Which of the following is the MOST significant concern?
Without business unit input, risk assessments focus on technical vulnerabilities rather than business impact. This can result in mitigation efforts that do not address the most critical risks to the organization. The most significant concern is that risk management becomes an IT-centric exercise, failing to align with enterprise risk management, which requires a business-driven perspective.
Why this answer
The most significant concern is that risk assessments performed solely by IT may not reflect business impact. Effective IT risk management requires collaboration between IT and business units to ensure that risks are evaluated in terms of their potential effect on business objectives. Without this, mitigation efforts may be misdirected, and critical business risks may be overlooked.
Exam trap
The trap here is focusing on the frequency or independence of risk assessments rather than the critical need for business involvement to assess impact.