CRISC Risk and Control Monitoring and Reporting 1 — Questions and Answers
Question 1: What is the primary purpose of continuous risk monitoring in CRISC?
- To detect changes in the risk environment and verify that controls remain effective over time (Correct answer)
- To replace periodic risk assessments entirely
- To document incidents for regulatory reporting purposes only
- To monitor employee compliance with acceptable use policies
Correct answer: To detect changes in the risk environment and verify that controls remain effective over time
Continuous risk monitoring ensures that the organization maintains awareness of its risk profile and quickly identifies when new risks emerge or existing controls degrade.
Question 2: What is a Key Risk Indicator (KRI)?
- A metric that provides early warning signals of increasing risk exposure (Correct answer)
- A measure of how effective a specific control is operating
- A financial report summarizing IT costs
- A checklist used during security audits
Correct answer: A metric that provides early warning signals of increasing risk exposure
KRIs are forward-looking metrics designed to signal when risk levels are trending toward or beyond acceptable thresholds before an incident occurs.
Question 3: How does a KRI differ from a Key Performance Indicator (KPI)?
- KRIs indicate potential future risk exposure; KPIs measure current control and process performance (Correct answer)
- KPIs are used only in financial reporting; KRIs apply only to IT systems
- Both measure the same thing but use different scales
- KRIs measure past incidents; KPIs predict future risk
Correct answer: KRIs indicate potential future risk exposure; KPIs measure current control and process performance
KRIs are predictive, warning of emerging risks, while KPIs are diagnostic, measuring how well current controls and processes are performing.
Question 4: What information should a risk report to senior management typically include?
- Current risk status, changes since last reporting period, KRI trends, and recommendations for action (Correct answer)
- Only a list of all identified risks without prioritization
- Technical details of every vulnerability found during the period
- Detailed firewall configuration settings
Correct answer: Current risk status, changes since last reporting period, KRI trends, and recommendations for action
Executive risk reports should summarize the risk landscape in business terms, highlight changes and trends, and provide actionable recommendations.
Question 5: What is the purpose of a control self-assessment (CSA)?
- To allow process owners to evaluate the effectiveness of controls over their own activities (Correct answer)
- To replace external audits entirely
- To automatically remediate control deficiencies using AI tools
- To assign blame for security incidents to specific teams
Correct answer: To allow process owners to evaluate the effectiveness of controls over their own activities
CSA empowers process owners to assess whether controls in their area are operating effectively, promoting ownership and often uncovering issues before formal audits.
Question 6: Which of the following indicates a control deficiency that requires immediate escalation?
- A critical control has failed and the resulting risk now exceeds the organization's risk tolerance (Correct answer)
- A low-priority system does not have a documented backup procedure
- A non-critical application lacks multi-factor authentication
- An internal policy has not been reviewed within the past 24 months
Correct answer: A critical control has failed and the resulting risk now exceeds the organization's risk tolerance
When a failed control causes risk to exceed tolerance, immediate escalation is required because the organization is operating outside its acceptable risk boundaries.
What is the primary purpose of continuous risk monitoring in CRISC?