Isaca Certified in Risk and Information Systems Control CRISC Question # 16 Topic 2 Discussion
CRISC Exam Topic 2 Question 16 Discussion:
Question #: 16
Topic #: 2
An organization is outsourcing a key database to be hosted by an external service provider. Who is BEST suited to assess the impact of potential data loss?
The business manager understands how data loss affects operations, revenue, and compliance — making them best positioned to assess impact.
ISACA guidance:
“Business process owners or business managers are responsible for identifying and assessing business impacts resulting from data loss or system unavailability.”
Technical roles may estimate likelihood or technical details, but impact assessment is a business responsibility.
Hence, C is correct.
CRISC Reference: Domain 2 – IT Risk Assessment, Topic: Business Impact Assessment.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit