CRISC Certified in Risk and Information Systems Control – Question854

Which of the following is the MOST important consideration when identifying stakeholders to review risk scenarios developed by a risk analyst? The reviewers are:

A.
authorized to select risk mitigation options.
B. independent from the business operations.
C. accountable for the affected processes.
D. members of senior management.

Correct Answer: B

CRISC Certified in Risk and Information Systems Control – Question853

Which of the following would be the BEST justification to invest in the development of a governance, risk, and compliance (GRC) solution?

A.
Facilitating risk-aware decision making by stakeholders.
B. Demonstrating management commitment to mitigate risk.
C. Closing audit findings on a timely basis.
D. Ensuring compliance to industry standards.

Correct Answer: A

CRISC Certified in Risk and Information Systems Control – Question850

Which of the following is the BEST key performance indicator (KPI) for determining how well an IT policy is aligned to business requirements?

A.
Total cost of policy breaches.
B. Total cost to support the policy.
C. Number of exceptions to the policy.
D. Number of inquiries regarding the policy.

Correct Answer: C

CRISC Certified in Risk and Information Systems Control – Question849

An organization has identified that terminated employee accounts are not disabled or deleted within the time required by corporate policy. Unsure of the reason, the organization has decided to monitor the situation for three months to obtain more information. As a result of this decision, the risk has been:

A.
accepted.
B. transferred.
C. avoided.
D. mitigated.

Correct Answer: A

CRISC Certified in Risk and Information Systems Control – Question848

An IT organization is replacing the customer relationship management (CRM) system. Who should own the risk associated with customer data leakage caused by insufficient IT security controls for the new system?

A.
Chief risk officer
B. IT controls manager
C. Chief information security officer
D. Business process owner

Correct Answer: D

CRISC Certified in Risk and Information Systems Control – Question846

Which of the following is MOST important for an organization that wants to reduce IT operational risk?

A.
Decentralizing IT infrastructure.
B. Increasing the frequency of data backups.
C. Increasing senior management’s understanding of IT operations.
D. Minimizing complexity of IT infrastructure.

Correct Answer: C