A risk manager is reviewing the risk report content for a quarterly IT risk committee meeting. Which TWO items are most important to include in the report?
A risk heat map gives the committee an aggregated, visual view of likelihood and impact across the portfolio, enabling prioritisation and comparison of exposures. This satisfies the stem's requirement for the most important content in a quarterly IT risk committee report.
Why this answer
A risk heat map (A) is essential because it visually prioritizes risks by likelihood and impact, allowing the IT risk committee to quickly identify and compare exposure across the risk portfolio. Top risks and their status (D) must be included so the committee can focus on the most significant threats, track mitigation progress, and make informed governance decisions. Individual employee performance metrics (B) are an HR concern and do not reflect organizational risk posture.
Detailed technical logs (C) are too granular and operational for a quarterly executive-level risk report. A list of all IT assets (E) is an inventory artifact, not a risk report element, and would overwhelm the committee without risk context.
Exam trap
The trap here is that candidates confuse operational data (like logs or asset lists) with strategic risk reporting content, failing to recognize that the committee needs summarized, decision-supporting visuals (heat map) and prioritized risk status, not raw technical details.