Which of the following should be identified FIRST when determining appropriate IT key risk indicators (KRIs)?
Correct Answer: A
IT key risk indicators (KRIs) are metrics that measure the likelihood and impact of IT-related risks on the enterprise's objectives and goals. Therefore, the first step in determining appropriate IT KRIs is to identify the IT-related risks that are relevant and significant for the enterprise. IT controls, IT threats and IT objectives are also important factors in developing IT KRIs, but they are not the first step. IT controls are the measures that mitigate or reduce IT risks, IT threats are the sources of potential harm or loss to IT assets or processes, and IT objectives are the desired outcomes or results of IT activities that support the enterprise's strategy and goals.
References := ISACA, CGEIT Review Manual, 7th Edition, 2019, p. 90-91; Integrating KRIs and KPIs for Effective Technology Risk Management; Performance Measurement Metrics for IT Governance; State and Impact of Governance of Enterprise IT in Organizations: Key Findings of an International Study.