13 - Risk Program Maturity Assessment
13 - Risk Program Maturity Assessment
13 - Risk Program Maturity Assessment
This assessment is part of ISACA’s IT Risk Starter Kit. The purpose of the IT Risk
Program Maturity Assessment is to identify the program’s current level of
maturity and to identify priorities for further development. This assessment is
intended to be illustrative, not comprehensive, and should be customized to suit
the specific enterprise environment.
Classification: Internal
Each level identified in the following table describes attributes that may or may not exist as part of an
enterprise risk management program. This table can be used to assess the level of maturity of an
enterprise based on the description of each level. Each description is meant to be general. Assessors
should use their own experience and discretion when determining the maturity level based on the
specific attributes of the entity being assessed.
Classification: Internal