CRISC Certified in Risk and Information Systems Control – Question463

Which of the following is the BEST metric to demonstrate the effectiveness of an organization’s change management process?

A.
Average time to complete changes
B. Increase in the number of emergency changes
C. Percent of unauthorized changes
D. Increase in the frequency of changes

Correct Answer: A

CRISC Certified in Risk and Information Systems Control – Question461

The PRIMARY reason, a risk practitioner would be interested in an internal audit report is to:

A.
maintain a risk register based on noncompliances
B. plan awareness programs for business managers
C. assist in the development of a risk profile
D. evaluate maturity of the risk management process

Correct Answer: D

CRISC Certified in Risk and Information Systems Control – Question458

The PRIMARY benefit of conducting continuous monitoring of access controls is the ability to identify.

A.
possible noncompliant activities that lead to data disclosure
B. leading or lagging key risk indicators (KRIs)
C. inconsistencies between security policies and procedures
D. unknown threats to undermine existing access controls

CRISC Certified in Risk and Information Systems Control – Question456

If preventive controls cannot be implemented due to technology limitations, which of the following should be done FIRST to reduce risk?

A.
Redefine the business process to reduce the risk
B. Evaluate alternative controls
C. Develop a plan to upgrade technology
D. Define a process for monitoring risk

Correct Answer: B