When presenting risk, the BEST method to ensure that the risk is measurable against the organization's risk appetite is through the use of a:
Correct Answer: A
A risk map is the best method to ensure that the risk is measurable against the organization's risk appetite, as it is a graphical tool that displays the level and priority of risks based on their likelihood and impact, as well as other factors such as velocity, persistence, and urgency. A risk map can help to compare and communicate the risk levels across different business units, processes, and projects, and to align them with the organization's risk appetite and tolerance. A risk map can also help to identify the gaps and overlaps in risk management, and to support the decision making and resource allocation for risk response. A cause-and-effect diagram is a tool that helps to identify and analyze the root causes and consequences of a risk or a problem, but it does not measure the risk against the organization's risk appetite. A maturity model is a tool that helps to assess and improve the capability and performance of a process or a function, but it does not measure the risk against the organization's risk appetite. A technology strategy plan is a document that outlines the vision, goals, and objectives of the organization's use of information and technology, but it does not measure the risk against the organization's risk appetite. References = Risk and Information Systems Control Study Manual, Chapter 3: IT Risk Assessment, page 97.