CRISC Certified in Risk and Information Systems Control – Question734

Which of the following risk management practices BEST facilitates the incorporation of IT risk scenarios into the enterprise-wide risk register?

A.
Key risk indicators (KRIs) are developed for key IT risk scenarios.
B. IT risk scenarios are developed in the context of organizational objectives.
C. IT risk scenarios are assessed by the enterprise risk management team.
D. Risk appetites for IT risk scenarios are approved by key business stakeholders.

Correct Answer: B

CRISC Certified in Risk and Information Systems Control – Question731

Which of the following is the BEST way for a risk practitioner to help management prioritize risk response?

A.
Assess risk against business objectives.
B. Implement an organization-specific risk taxonomy.
C. Align business objectives to the risk profile.
D. Explain risk details to management.

Correct Answer: C

CRISC Certified in Risk and Information Systems Control – Question730

Whether the results of risk analysis should be presented in quantitative or qualitative terms should be based PRIMARILY on the:

A.
specific risk analysis framework being used.
B. results of the risk assessment.
C. requirements of management.
D. organizational risk tolerance.

Correct Answer: A

CRISC Certified in Risk and Information Systems Control – Question727

Senior management has asked a risk practitioner to develop technical risk scenarios related to a recently developed enterprise resource planning (ERP) system. These scenarios will be owned by the system manager. Which of the following would be the BEST method to use when developing the scenarios?

A.
Bottom-up approach
B. Cause-and-effect diagram
C. Top-down approach
D. Delphi technique

Correct Answer: D

CRISC Certified in Risk and Information Systems Control – Question725

A business unit is updating a risk register with assessment results for a key project. Which of the following is MOST important to capture in the register?

A.
Action plans to address risk scenarios requiring treatment
B. The team that performed the risk assessment
C. An assigned risk manager to provide oversight
D. The methodology used to perform the risk assessment

Correct Answer: D