nerdexam
Isaca

CRISC · Question #176

An organization's business gap analysis reveals the need for a robust IT risk strategy. Which of the following should be the risk practitioner's PRIMARY consideration when participating in development

The correct answer is C. Risk culture. When developing a new IT risk strategy, the risk practitioner's primary consideration should be the organization's risk culture.

Submitted by ngozi_ng· Apr 18, 2026Governance

Question

An organization's business gap analysis reveals the need for a robust IT risk strategy. Which of the following should be the risk practitioner's PRIMARY consideration when participating in development of the new strategy?

Options

  • AScale of technology
  • BRisk indicators
  • CRisk culture
  • DProposed risk budget

How the community answered

(32 responses)
  • A
    13% (4)
  • B
    9% (3)
  • C
    75% (24)
  • D
    3% (1)

Why each option

When developing a new IT risk strategy, the risk practitioner's primary consideration should be the organization's risk culture.

AScale of technology

The scale of technology is a factor in identifying specific risks and controls, but less foundational than the overall risk culture for strategy development.

BRisk indicators

Risk indicators are tools for monitoring risk, which come *after* the strategy defines what to monitor and why.

CRisk cultureCorrect

Risk culture encompasses the shared attitudes, values, and practices that characterize how an organization perceives and responds to risk. A strategy, no matter how robust, will fail if it's not aligned with or doesn't seek to influence the underlying culture regarding risk-taking and compliance.

DProposed risk budget

The proposed risk budget is an important resource constraint, but the strategy needs to align with the organization's willingness and ability to manage risk, which is shaped by culture.

Concept tested: Risk strategy development factors (culture)

Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/security-governance#risk-management-framework

Topics

#IT Risk Strategy#Risk Culture#Strategic Planning#Organizational Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice