CRISC Risk Governance and Frameworks 2 — Questions and Answers
Question 1: COBIT 2019 supports CRISC practitioners PRIMARILY by providing which capability?
- A governance and management framework for enterprise IT (Correct answer)
- A technical standard for network security
- A methodology for software development
- A database of known vulnerabilities
Correct answer: A governance and management framework for enterprise IT
COBIT 2019 provides an enterprise IT governance and management framework that aligns IT objectives with business goals and risk management.
Question 2: Which risk governance document defines the boundaries within which business units must manage their risk?
- Risk policy (Correct answer)
- Risk register
- Business impact analysis
- Vulnerability assessment report
Correct answer: Risk policy
A risk policy establishes the organization's overall approach, boundaries, and mandates for how risk must be managed across all business units.
Question 3: A company's IT risk governance structure is WEAK when which condition exists?
- Risk decisions are made without senior management involvement (Correct answer)
- Risk assessments are conducted annually
- Risk owners are assigned for each identified risk
- Risk appetite is documented and communicated
Correct answer: Risk decisions are made without senior management involvement
When risk decisions lack senior management involvement, governance is weak because strategic alignment and accountability are absent.
Question 4: Which principle is MOST critical when integrating IT risk management into corporate governance?
- Alignment of IT risk with business objectives (Correct answer)
- Use of automated risk assessment tools
- Separation of IT operations from risk management
- Quarterly reporting of all identified risks
Correct answer: Alignment of IT risk with business objectives
IT risk management must be aligned with business objectives to ensure governance decisions support the organization's overall strategic direction.
Question 5: In a risk governance framework, the risk owner is BEST described as the person who:
- Is accountable for managing the risk to acceptable levels (Correct answer)
- Performs the daily monitoring of risk controls
- Identifies new risks during assessments
- Reports risk metrics to the board
Correct answer: Is accountable for managing the risk to acceptable levels
The risk owner is accountable for ensuring a specific risk is managed within acceptable levels and that appropriate controls are in place.
Question 6: Which characteristic distinguishes a mature IT risk governance program from an immature one?
- Risk management is proactive and integrated into decision-making (Correct answer)
- Risk assessments are performed after incidents occur
- IT risk is managed solely by the IT department
- Risk policies are reviewed every five years
Correct answer: Risk management is proactive and integrated into decision-making
Mature IT risk governance integrates risk considerations proactively into all business decisions rather than reacting to incidents after the fact.
COBIT 2019 supports CRISC practitioners PRIMARILY by providing which capability?