Isaca Certified in Risk and Information Systems Control CRISC Question # 231 Topic 24 Discussion
CRISC Exam Topic 24 Question 231 Discussion:
Question #: 231
Topic #: 24
An organization has just implemented changes to close an identified vulnerability that impacted a critical business process. What should be the NEXT course of action?
According to the CRISC Review Manual1, the risk register is a tool that records the results of risk identification, analysis, evaluation, and treatment. It should be updated whenever there is a change in the risk profile, such as when a vulnerability is closed or a new threat is identified. Updating the risk register allows the organization to monitor the current status of risks and the effectiveness of risk responses. Therefore, the next course of action after implementing changes to close an identifiedvulnerability is to update the risk register with the new information. References = CRISC Review Manual1, page 191.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit