The BEST answer is B because continuous monitoring must be tied to defined thresholds, risk appetite/tolerance, and business objectives. A policy should state what is monitored, what thresholds trigger escalation, and how those thresholds support organizational objectives. ISACA’s CRISC exam outline includes “risk and control metrics,” “risk and control monitoring techniques,” “monitoring and reporting of emerging risks,” and the supporting task to assist stakeholders with “risk appetite and tolerance thresholds and the impact on business objectives.” The uploaded CRISC notes also support this: continuous monitoring detects changes in the enterprise risk environment, risk appetite should align with business objectives, and thresholds are important when developing monitoring metrics.
A is incorrect because standardizing mitigation may help consistency, but it does not define monitoring thresholds or alignment to objectives. C is governance-focused but does not directly incorporate continuous monitoring into policy. D is incorrect because a GRC tool may support monitoring, but tools do not replace policy definition.
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit