CRISC Certified in Risk and Information Systems Control – Question632

After the review of a risk record, internal audit questioned why the risk was lowered from medium to low. Which of the following is the BEST course of action in responding to this inquiry?

A.
Notify the business at the next risk briefing
B. Obtain industry benchmarks related to the specific risk
C. Provide justification for the lower risk rating
D. Reopen the risk issue and complete a full assessment

Correct Answer: C