CRISC Certified in Risk and Information Systems Control – Question177

Which of the following guidelines should be followed for effective risk management? Each correct answer represents a complete solution. Choose three.

A.
Promote and support consistent performance in risk management
B. Promote fair and open communication
C. Focus on enterprise's objective
D. Balance the costs and benefits of managing risk

Correct Answer: BCD

Explanation:

Explanation: The primary function of the enterprise is to meet its objective. Each business activity for fulfilling enterprise’s objective carries both risk and opportunity, therefore objective should be considered while managing risk.
Open and fair communication should me there for effective risk management. Open, accurate, timely and transparent information on lT risk is exchanged and serves as the basis for all risk-related decisions.
Cost-benefit analysis should be done for proper weighing the total costs expected against the total benefits expected, which is the major aspect of risk management.
Incorrect Answers:
A: For effective risk management, there should be continuous improvement, not consistent. Because of the dynamic nature of risk, risk management is an iterative, perpetual and ongoing process; that’s why, continuous improvement is required.