CRISC Certified in Risk and Information Systems Control – Question753

Which of the following issues regarding an organization's IT incident response plan would be the GREATEST concern?

A.
The incident response capability is outsourced.
B. Teams are not operational until an incident occurs.
C. Not all employees have attended incident response training.
D. Roles and responsibilities are not clearly defined.

Correct Answer: D

CRISC Certified in Risk and Information Systems Control – Question752

Which of the following is the STRONGEST indication that controls implemented as part of a risk action plan are not effective?

A.
A security breach occurs.
B. Internal audit identifies recurring exceptions.
C. Changes are put into production without management approval.
D. A sample is used to validate the action plan.

Correct Answer: B

CRISC Certified in Risk and Information Systems Control – Question750

Which of the following would BEST help identify the owner for each risk scenario in a risk register?

A.
Allocating responsibility for risk factors equally to asset owners.
B. Determining resource dependency of assets.
C. Mapping identified risk factors to specific business processes.
D. Determining which departments contribute most to risk.

Correct Answer: C

CRISC Certified in Risk and Information Systems Control – Question749

A data processing center operates in a jurisdiction where new regulations have significantly increased penalties for data breaches. Which of the following elements of the risk register is MOST important to update to reflect this change?

A.
Risk impact
B. Risk trend
C. Risk appetite
D. Risk likelihood

Correct Answer: C