CRISC Certified in Risk and Information Systems Control – Question186

Beth is a project team member on the JHG Project. Beth has added extra features to the project and this has introduced new risks to the project work. The project manager of the JHG project elects to remove the features Beth has added. The process of removing the extra features to remove the risks is called what?

A.
Detective control
B. Preventive control
C. Corrective control
D. Scope creep

Correct Answer: B

Explanation:

Explanation:
This is an example of a preventive control as the problem is not yet occurred, only it is detected and are accounted for. By removing the scope items from the project work, the project manager is aiming to remove the added risk events, hence it is a preventive control. Preventive control is a type of internal control that is used to avoid undesirable events, errors and other occurrences, which an organization has determined could have a negative material effect on a process or end product.
Incorrect Answers:
A: Detective controls simply detect and report on the occurrence of problems. They identify specific symptoms to potential problems.
C: Corrective actions are steps to bring the future performance of the project work in line with the project management plan. These controls make effort to reduce the impact of a threat from problems discovered by detective controls. They first identify the cause of the problems, then take corrective measures and modify the systems to minimize the future occurrences of the problem. Hence an incident should take place before corrective controls come in action.
D: Scope creep refers to small undocumented changes to the project scope.