Correct Answer: D
An operational risk assessment is the most effective way of assessing enterprise risk, as it evaluates the potential losses and impacts that may arise from inadequate or failed internal processes, people, systems, or external events. An operational risk assessment also helps to identify and prioritize the key risk indicators (KRIs), risk scenarios, and mitigation strategies for the enterprise12. References := CGEIT Exam Content Outline, Domain 4, Subtopic B: IT Risk Management, Task 1: Ensure that an IT risk management framework exists to identify, analyze, mitigate, manage, monitor, and communicate IT-related business risk, and that the framework for IT risk management is in alignment with the enterprise risk management (ERM) framework.