Deck 12: The Risk Intelligent Enterprise: Enterprise Risk Management

ملء الشاشة (f)
exit full mode
سؤال
Which of the following is NOT part of IT controls?

A)Event controls
B)IT general controls
C)Entity-level controls
D)Application controls
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
What is risk intelligence?
سؤال
Enterprise risk management (ERM)goes beyond just security and controls.
سؤال
A silo approach with separate departments developing separate security programs without consideration of comprehensive risk management can prove to be very effective.
سؤال
Risk intelligence involves using risk in a pro active, constructive way to create additional value for the enterprise.
سؤال
The SEC requires company boards to report in-depth on how their enterprises identify risk, set risk tolerances, and manage risk/reward trade-offs.
سؤال
The IT control associated with top management is

A)IT general controls
B)Entity-level controls
C)Application controls
D)Event controls
سؤال
Identifying, assessing, and mitigating risks has not been shown to produce better business performance.
سؤال
Controls are not task driven. Understanding risk is not a prerequisite to the appreciation and application of control.
سؤال
________ risks have no benefits, only threats to success.
سؤال
At the top management level, ________ IT controls provide IT governance that sets the tone from the top of the enterprise.
سؤال
________ risks have the possibility of benefits associated with it.
سؤال
What percentage of CFOs provide advice on enterprise risk management?

A)63%
B)58%
C)79%
D)83%
سؤال
Which of the following is NOT considered part of IT controls?

A)ERM
B)Application controls
C)Entity-level controls
D)IT general controls
سؤال
The International Organization for Standardization framework for risk management is ________.
سؤال
Risk management shifts an enterprise from a pro active approach of anticipating and mitigating future risks before incidents occur to a reactive approach.
سؤال
The IT control associated with business processes is

A)Entity-level controls
B)IT general controls
C)Application controls
D)Event controls
سؤال
________ are controls embedded in business processes where a majority of security breaches occur.
سؤال
Application controls are controls over IT services, such as networks and database systems.
سؤال
Which of the following titles does NOT refer to someone in the C-Suite?

A)CIO: Chief Information Officer
B)CSO: Chief Sustainability Officer
C)CIA: Certified Internal Auditor
D)CFO: Chief Financial Officer
سؤال
Match the ERM component name to the appropriate definition.

-Internal Environment

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
Which of the following is NOT a dimension in an ERM cube?

A)ERM resources
B)ERM objectives
C)ERM components
D)ERM units
سؤال
Which ERM component involves the risk management philosophy of the enterprise,including the tone set by top management?

A)Control activities
B)Information and communication
C)Internal environment
D)Event identification
سؤال
________ is a COSO framework that provides guidance for managing risk.
سؤال
Match the ERM Objective with the appropriate definition.

-Reporting objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
سؤال
Match the ERM component name to the appropriate definition.

-Control activities

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
Given the impossibility of foreseeing every conceivable control to address all threats, risk management uses the approach of assessing risk to determine the probability of risk, its frequency, and its impact.
سؤال
Match the ERM component name to the appropriate definition.

-Monitoring

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
Which ERM objective relates to the effective and efficient use of a corporation's resources?

A)Operational objective
B)Compliance objective
C)Strategic objective
D)Reporting objective
سؤال
It is possible for a company to be 100% risk free.
سؤال
The COSO Enterprise Risk Management framework replaces the COSO framework for internal control.
سؤال
Match the ERM Objective with the appropriate definition.

-Compliance objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
سؤال
Match the ERM Objective with the appropriate definition.

-Strategic objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
سؤال
Match the ERM Objective with the appropriate definition.

-Operational objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
سؤال
Which ERM objective relates to the goals that support a corporation's mission?

A)Reporting objective
B)Operational objective
C)Strategic objective
D)Compliance objective
سؤال
What is the difference between downside risks and upside risks?
سؤال
Which of the following is part of the ERM units?

A)Internal Environments
B)Entity-level
C)Operations
D)Monitoring
سؤال
Match the ERM component name to the appropriate definition.

-Information and communication

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
Match the ERM component name to the appropriate definition.

-Objective setting

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
Match the ERM component name to the appropriate definition.

-Event identification

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
سؤال
In the context of enterprise risk management, ________ refers to the process of monitoring an entity's enterprise risk management.
سؤال
Match the word to the appropriate sentence to complete the risk response definition.

-Sharing

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
سؤال
________ forms the basis for operations, reporting, and compliance objectives.
سؤال
________ is the acceptable level of variation in attaining objectives.
سؤال
What is the main limitation in the ERM framework? Why is it a limitation?
سؤال
List and define the eight interrelated ERM components.
سؤال
In ERM risk assessment, ________ may refer to assessing likelihood using qualitative measures, such as high, medium, or low.
سؤال
In ERM risk assessment, possibility may refer to assessing likelihood using a quantitative measure, such as percentages.
سؤال
________ is the process of assessing the extent to which events would impact an entity's ability to achieve its objectives.
سؤال
The ________ is also impacted by human resource policies, including hiring practices.
سؤال
List and define the four categories in the ERM framework of an enterprise's objectives.
سؤال
In ERM risk assessment, ________ may refer to assessing likelihood using a quantitative measure, such as percentages.
سؤال
The ________ component involves identifying potential events that might affect the entity.
سؤال
When risk responses are being considered, the costs and benefits of options may play a major role in the final decision.
سؤال
The integrated enterprise system is unable to provide management with additional data and information for use in making enterprise risk management assessments and decisions.
سؤال
The ________ relates to the culture of the organization and its risk consciousness.
سؤال
Which ERM component is comprised of policies and procedures established and implemented to ensure risk responses are effective?

A)Risk assessment
B)Control activities
C)Information and communication
D)Objective setting
سؤال
Match the word to the appropriate sentence to complete the risk response definition.

-Reduce

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
سؤال
A well developed and articulated risk management philosophy can provide consistency in risk attitudes throughout the entire enterprise.
سؤال
Match the word to the appropriate sentence to complete the risk response definition.

-Avoiding

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
سؤال
Which question pertains to assessing risk likelihood?

A)What is the estimated frequency of the threat occurring?
B)What is the asset's value?
C)What is the estimated potential loss per threat?
D)How much is the asset worth to the competition?
سؤال
Match the IT control activity to the appropriate enterprise level.

-Entity-level IT controls

A)IT governance
B)Business processes
C)IT processes and services
سؤال
Qualitative measures include

A)Means
B)Regression
C)Percentages
D)Ranking likelihood
سؤال
What are the four risk response categories? Include a definition of each.
سؤال
Match the IT control activity to the appropriate enterprise level.

-IT general controls

A)IT governance
B)Business processes
C)IT processes and services
سؤال
What are five external events that may pose a risk to an enterprise's ability to achieve objectives? Provide examples.
سؤال
Operation objectives relate to

A)The reliability of both internal and external reports, including both financial and nonfinancial information
B)The effective and efficient use of the entity's resources
C)An entity's compliance with applicable laws and regulations
D)An entity's ability to mitigate risk
سؤال
Match the IT control activity to the appropriate enterprise level.

-Application controls

A)IT governance
B)Business processes
C)IT processes and services
سؤال
Match the word to the appropriate sentence to complete the risk response definition.

-Acceptance

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
سؤال
What are four internal events that may pose a risk to an enterprise's ability to achieve objectives? Provide examples.
سؤال
Assessment techniques used to assess risk are grouped into two categories. What are these categories? Define each.
سؤال
Which of the following is NOT an external factor that might affect an enterprise's ability to achieve objectives?

A)Economic events
B)Natural environment
C)Processes
D)Political events
سؤال
Which of the following is an incident or occurrence that originates inside an organization?

A)Changes in regulations
B)Data integrity
C)New technology
D)Product competition
سؤال
The risk time frame ________ relates to the organization's strategy, affecting three to five years or longer.
سؤال
Which of the following is both an internal and external factor that might affect an enterprise's ability to achieve objectives?

A)Infrastructures
B)Technology events
C)Economic events
D)Social events
سؤال
Which of the following is NOT considered a control activity?

A)Locked door
B)Performance reviews
C)Event identification
D)Segregation of duties
سؤال
Hiring competent employees who are provided ongoing training

A)Can increase risks from accidents and errors
B)Can increase the amount of fraud
C)Can reduce risks from accidents and errors
D)Can reduce an enterprise's risk tolerance
سؤال
ISO 13000 is not the only internationally accepted enterprise risk management standard.
سؤال
Which of the following is NOT an incident or occurrence that originates outside an organization?

A)Changes in consumer demographics
B)New legislation
C)Employee competence
D)Liquidity factors
سؤال
What is risk tolerance? Provide an example.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/108
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 12: The Risk Intelligent Enterprise: Enterprise Risk Management
1
Which of the following is NOT part of IT controls?

A)Event controls
B)IT general controls
C)Entity-level controls
D)Application controls
A
2
What is risk intelligence?
Risk intelligence moves beyond just managing risk to using risk intelligently to create value for the enterprise. Some risk has only a downside or loss associated with it, such as computer viruses that destroy corporate emails. Risk intelligence includes managing not only adverse risks, but also capitalizing on risk that presents the enterprise with opportunities to create value, such as evaluating risk associated with a new business acquisition.
3
Enterprise risk management (ERM)goes beyond just security and controls.
True
4
A silo approach with separate departments developing separate security programs without consideration of comprehensive risk management can prove to be very effective.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
5
Risk intelligence involves using risk in a pro active, constructive way to create additional value for the enterprise.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
6
The SEC requires company boards to report in-depth on how their enterprises identify risk, set risk tolerances, and manage risk/reward trade-offs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
7
The IT control associated with top management is

A)IT general controls
B)Entity-level controls
C)Application controls
D)Event controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
8
Identifying, assessing, and mitigating risks has not been shown to produce better business performance.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
9
Controls are not task driven. Understanding risk is not a prerequisite to the appreciation and application of control.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
10
________ risks have no benefits, only threats to success.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
11
At the top management level, ________ IT controls provide IT governance that sets the tone from the top of the enterprise.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
12
________ risks have the possibility of benefits associated with it.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
13
What percentage of CFOs provide advice on enterprise risk management?

A)63%
B)58%
C)79%
D)83%
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
14
Which of the following is NOT considered part of IT controls?

A)ERM
B)Application controls
C)Entity-level controls
D)IT general controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
15
The International Organization for Standardization framework for risk management is ________.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
16
Risk management shifts an enterprise from a pro active approach of anticipating and mitigating future risks before incidents occur to a reactive approach.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
17
The IT control associated with business processes is

A)Entity-level controls
B)IT general controls
C)Application controls
D)Event controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
18
________ are controls embedded in business processes where a majority of security breaches occur.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
19
Application controls are controls over IT services, such as networks and database systems.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
20
Which of the following titles does NOT refer to someone in the C-Suite?

A)CIO: Chief Information Officer
B)CSO: Chief Sustainability Officer
C)CIA: Certified Internal Auditor
D)CFO: Chief Financial Officer
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
21
Match the ERM component name to the appropriate definition.

-Internal Environment

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
22
Which of the following is NOT a dimension in an ERM cube?

A)ERM resources
B)ERM objectives
C)ERM components
D)ERM units
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
23
Which ERM component involves the risk management philosophy of the enterprise,including the tone set by top management?

A)Control activities
B)Information and communication
C)Internal environment
D)Event identification
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
24
________ is a COSO framework that provides guidance for managing risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
25
Match the ERM Objective with the appropriate definition.

-Reporting objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
26
Match the ERM component name to the appropriate definition.

-Control activities

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
27
Given the impossibility of foreseeing every conceivable control to address all threats, risk management uses the approach of assessing risk to determine the probability of risk, its frequency, and its impact.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
28
Match the ERM component name to the appropriate definition.

-Monitoring

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
29
Which ERM objective relates to the effective and efficient use of a corporation's resources?

A)Operational objective
B)Compliance objective
C)Strategic objective
D)Reporting objective
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
30
It is possible for a company to be 100% risk free.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
31
The COSO Enterprise Risk Management framework replaces the COSO framework for internal control.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
32
Match the ERM Objective with the appropriate definition.

-Compliance objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
33
Match the ERM Objective with the appropriate definition.

-Strategic objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
34
Match the ERM Objective with the appropriate definition.

-Operational objectives

A)These objectives relate to the reliability of the enterprise's reporting, both internal and external.
B)These objectives relate to the effective and efficient use of the entity's resources.
C)These objectives relate to goals that support the entity's mission.
D)These objectives relate to the entity's compliance with all applicable laws and regulations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
35
Which ERM objective relates to the goals that support a corporation's mission?

A)Reporting objective
B)Operational objective
C)Strategic objective
D)Compliance objective
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
36
What is the difference between downside risks and upside risks?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
37
Which of the following is part of the ERM units?

A)Internal Environments
B)Entity-level
C)Operations
D)Monitoring
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
38
Match the ERM component name to the appropriate definition.

-Information and communication

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
39
Match the ERM component name to the appropriate definition.

-Objective setting

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
40
Match the ERM component name to the appropriate definition.

-Event identification

A)This is comprised of policies and procedures established and implemented to ensure risk responses are effective.
B)This involves identifying occurrences that affect an enterprise's ability to attain its objectives.
C)This involves ensuring relevant data is captured and communicated effectively throughout the organization to appropriate individuals in a timely manner.
D)This involves watched evaluation and feedback that permits modifications as needed.
E)This ensures that the enterprise has a process for setting goals that are consistent with the entity's mission and risk appetite.
F)This involves the risk management philosophy of the enterprise, including the tone set by top management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
41
In the context of enterprise risk management, ________ refers to the process of monitoring an entity's enterprise risk management.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
42
Match the word to the appropriate sentence to complete the risk response definition.

-Sharing

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
43
________ forms the basis for operations, reporting, and compliance objectives.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
44
________ is the acceptable level of variation in attaining objectives.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
45
What is the main limitation in the ERM framework? Why is it a limitation?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
46
List and define the eight interrelated ERM components.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
47
In ERM risk assessment, ________ may refer to assessing likelihood using qualitative measures, such as high, medium, or low.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
48
In ERM risk assessment, possibility may refer to assessing likelihood using a quantitative measure, such as percentages.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
49
________ is the process of assessing the extent to which events would impact an entity's ability to achieve its objectives.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
50
The ________ is also impacted by human resource policies, including hiring practices.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
51
List and define the four categories in the ERM framework of an enterprise's objectives.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
52
In ERM risk assessment, ________ may refer to assessing likelihood using a quantitative measure, such as percentages.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
53
The ________ component involves identifying potential events that might affect the entity.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
54
When risk responses are being considered, the costs and benefits of options may play a major role in the final decision.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
55
The integrated enterprise system is unable to provide management with additional data and information for use in making enterprise risk management assessments and decisions.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
56
The ________ relates to the culture of the organization and its risk consciousness.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
57
Which ERM component is comprised of policies and procedures established and implemented to ensure risk responses are effective?

A)Risk assessment
B)Control activities
C)Information and communication
D)Objective setting
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
58
Match the word to the appropriate sentence to complete the risk response definition.

-Reduce

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
59
A well developed and articulated risk management philosophy can provide consistency in risk attitudes throughout the entire enterprise.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
60
Match the word to the appropriate sentence to complete the risk response definition.

-Avoiding

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
61
Which question pertains to assessing risk likelihood?

A)What is the estimated frequency of the threat occurring?
B)What is the asset's value?
C)What is the estimated potential loss per threat?
D)How much is the asset worth to the competition?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
62
Match the IT control activity to the appropriate enterprise level.

-Entity-level IT controls

A)IT governance
B)Business processes
C)IT processes and services
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
63
Qualitative measures include

A)Means
B)Regression
C)Percentages
D)Ranking likelihood
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
64
What are the four risk response categories? Include a definition of each.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
65
Match the IT control activity to the appropriate enterprise level.

-IT general controls

A)IT governance
B)Business processes
C)IT processes and services
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
66
What are five external events that may pose a risk to an enterprise's ability to achieve objectives? Provide examples.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
67
Operation objectives relate to

A)The reliability of both internal and external reports, including both financial and nonfinancial information
B)The effective and efficient use of the entity's resources
C)An entity's compliance with applicable laws and regulations
D)An entity's ability to mitigate risk
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
68
Match the IT control activity to the appropriate enterprise level.

-Application controls

A)IT governance
B)Business processes
C)IT processes and services
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
69
Match the word to the appropriate sentence to complete the risk response definition.

-Acceptance

A)An entity reduces risk likelihood or risk impact by ________ the risk with another entity.
B)This risk response refers to actions taken to ________ risk likelihood, risk impact, or both.
C)When an entity responds to risk with ________, the entity takes no action to affect risk likelihood or risk impact.
D)This risk response involves ________ or exiting the activities that give rise to the risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
70
What are four internal events that may pose a risk to an enterprise's ability to achieve objectives? Provide examples.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
71
Assessment techniques used to assess risk are grouped into two categories. What are these categories? Define each.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
72
Which of the following is NOT an external factor that might affect an enterprise's ability to achieve objectives?

A)Economic events
B)Natural environment
C)Processes
D)Political events
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
73
Which of the following is an incident or occurrence that originates inside an organization?

A)Changes in regulations
B)Data integrity
C)New technology
D)Product competition
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
74
The risk time frame ________ relates to the organization's strategy, affecting three to five years or longer.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
75
Which of the following is both an internal and external factor that might affect an enterprise's ability to achieve objectives?

A)Infrastructures
B)Technology events
C)Economic events
D)Social events
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
76
Which of the following is NOT considered a control activity?

A)Locked door
B)Performance reviews
C)Event identification
D)Segregation of duties
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
77
Hiring competent employees who are provided ongoing training

A)Can increase risks from accidents and errors
B)Can increase the amount of fraud
C)Can reduce risks from accidents and errors
D)Can reduce an enterprise's risk tolerance
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
78
ISO 13000 is not the only internationally accepted enterprise risk management standard.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
79
Which of the following is NOT an incident or occurrence that originates outside an organization?

A)Changes in consumer demographics
B)New legislation
C)Employee competence
D)Liquidity factors
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
80
What is risk tolerance? Provide an example.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 108 في هذه المجموعة.