Isaca Certified in Risk and Information Systems Control CRISC Question # 162 Topic 17 Discussion
CRISC Exam Topic 17 Question 162 Discussion:
Question #: 162
Topic #: 17
An organization maintains independent departmental risk registers that are not automatically aggregated. Which of the following is the GREATEST concern?
A.
Management may be unable to accurately evaluate the risk profile.
B.
Resources may be inefficiently allocated.
C.
The same risk factor may be identified in multiple areas.
D.
Multiple risk treatment efforts may be initiated to treat a given risk.
The greatest concern of maintaining independent departmental risk registers that are not automatically aggregated is that management may be unable to accurately evaluate the risk profile. The risk profile is the overall view of the risks that the organization faces and their impact on the organization’s objectives. It helps management to prioritize and allocate resources for risk management and to align the risk appetite and strategy. If the departmental risk registers are not aggregated, management may not have a complete and consistent picture of the risks across the organization. They may miss some important risks, overestimate or underestimate some risks, or have conflicting or redundant risk information. This may lead to poor risk management decisions and outcomes. The other options are also concerns, but they are not ascritical as the inability to evaluate the risk profile. References = Risk and Information Systems Control Study Manual, Chapter 2: IT Risk Assessment, Section 2.2: IT Risk Analysis, page 63.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit