A supervisor claims enterprise risk management is simply buying enterprise antivirus. What corrects that claim?
Select an answer to reveal the explanation.
Short Explanation
Antivirus is one lock on one door. ERM is the whole building plan—strategy, money, ops, and hazard risks—so calling a software buy “enterprise risk management” sells the job way short.
Full Explanation
Enterprise risk management encompasses a broad portfolio of risk types that can affect organizational objectives, including strategic, operational, financial, and hazard categories. Equating ERM with a single IT control misstates scope and leaves non-cyber exposures unmanaged at the enterprise level.