CRISC Certified in Risk and Information Systems Control – Question503

Which of the following activities would BEST contribute to promoting an organization-wide risk-aware culture?

A.
Communicating components of risk and their acceptable levels
B. Performing a benchmark analysis and evaluating gaps
C. Participating in peer reviews and implementing best practices
D. Conducting risk assessments and implementing controls

CRISC Certified in Risk and Information Systems Control – Question500

Which of the following is the BEST way to validate whether controls have been implemented according to the risk mitigation action plan?

A.
Implement key risk indicators (KRIs)
B. Test the control design
C. Test the control environment
D. Implement key performance indicators (KPIs)

Correct Answer: A

CRISC Certified in Risk and Information Systems Control – Question497

An organization has outsourced an application to a Software as a Service (SaaS) provider. The risk associated with the use of this service should be owned by the:

A.
service provider’s IT manager
B. service provider’s risk manager
C. organization’s business process manager
D. organization’s vendor manager

Correct Answer: C

CRISC Certified in Risk and Information Systems Control – Question495

Which of the following is the BEST method to maintain a common view of IT risk within an organization?

A.
Establishing and communicating the IT risk profile
B. Performing and publishing an IT risk analysis
C. Collecting data for IT risk assessment
D. Utilizing a balanced scorecard

Correct Answer: B