CRISC Risk and Control Monitoring and Reporting 2 — Questions and Answers
Question 1: What does a risk dashboard primarily provide to stakeholders?
- A real-time or near-real-time visual summary of the organization's risk posture and KRI status (Correct answer)
- A complete audit trail of all system changes
- Detailed technical vulnerability scan results
- Vendor contract performance metrics
Correct answer: A real-time or near-real-time visual summary of the organization's risk posture and KRI status
A risk dashboard aggregates KRIs and risk metrics into a visual format that enables quick understanding of the current risk posture without requiring detailed analysis.
Question 2: What is the purpose of tracking risk trends over time?
- To identify whether risks are increasing, decreasing, or stable so that responses can be adjusted accordingly (Correct answer)
- To provide evidence of compliance with regulatory requirements only
- To justify the IT security budget to the CFO
- To replace the need for periodic risk assessments
Correct answer: To identify whether risks are increasing, decreasing, or stable so that responses can be adjusted accordingly
Trend analysis reveals the direction risk is moving, enabling proactive adjustments to risk responses before situations deteriorate beyond acceptable thresholds.
Question 3: Which of the following is a typical trigger for updating the risk register?
- A significant change in the business environment, technology, or threat landscape (Correct answer)
- Only the completion of an annual audit cycle
- When a risk has been accepted and documented
- After risk responses have been fully implemented and verified
Correct answer: A significant change in the business environment, technology, or threat landscape
Material changes in the environment — such as new systems, mergers, emerging threats, or regulatory changes — should trigger an update to the risk register to keep it current.
Question 4: What is the significance of establishing control thresholds in risk monitoring?
- Thresholds define the acceptable performance range for controls, triggering alerts when breached (Correct answer)
- Thresholds determine the maximum IT budget for a fiscal year
- They eliminate the need for human review of control performance
- Thresholds are used only for financial controls, not IT controls
Correct answer: Thresholds define the acceptable performance range for controls, triggering alerts when breached
Control thresholds define the boundary of acceptable performance; when a metric crosses the threshold, it signals that human review and potential escalation are needed.
Question 5: What is the purpose of a lessons-learned review after a security incident?
- To analyze what happened, why controls failed, and how to prevent recurrence (Correct answer)
- To assign legal liability for the incident to specific parties
- To document the incident solely for insurance claim purposes
- To satisfy auditor requirements without making actual process changes
Correct answer: To analyze what happened, why controls failed, and how to prevent recurrence
Lessons-learned reviews close the risk management loop by identifying root causes, control weaknesses, and improvements to prevent the same incident from recurring.
Question 6: What role does internal audit play in the risk monitoring process?
- Providing independent assurance that risk management processes and controls are operating effectively (Correct answer)
- Directly managing IT risks on behalf of the risk function
- Setting the organization's risk appetite and tolerance levels
- Approving all risk treatment plans before implementation
Correct answer: Providing independent assurance that risk management processes and controls are operating effectively
Internal audit provides objective, independent validation that the risk management framework and controls are functioning as intended, without conflicts of interest.
What does a risk dashboard primarily provide to stakeholders?