nerdexam
Isaca

CRISC · Question #177

A risk practitioner implemented a process to notify management of emergency changes that may not be approved. Which of the following is the BEST way to provide this information to management?

The correct answer is D. Key risk indicators (KRIs). The best way to inform management about emergency, potentially unapproved changes is through Key Risk Indicators (KRIs).

Submitted by dimitri_ru· Apr 18, 2026Risk Response and Reporting

Question

A risk practitioner implemented a process to notify management of emergency changes that may not be approved. Which of the following is the BEST way to provide this information to management?

Options

  • AChange logs
  • BChange management meeting minutes
  • CKey control indicators (KCIs)
  • DKey risk indicators (KRIs)

How the community answered

(70 responses)
  • A
    9% (6)
  • B
    3% (2)
  • C
    16% (11)
  • D
    73% (51)

Why each option

The best way to inform management about emergency, potentially unapproved changes is through Key Risk Indicators (KRIs).

AChange logs

Change logs record changes but don't inherently highlight the *risk* associated with unapproved emergency changes for management.

BChange management meeting minutes

Meeting minutes document discussions but are reactive and not a proactive mechanism for alerting management to a specific risk arising from emergency changes.

CKey control indicators (KCIs)

KCIs measure the effectiveness of controls, but KRIs specifically focus on the *risk* level, which is more appropriate for notifying management about potential unapproved changes.

DKey risk indicators (KRIs)Correct

KRIs are metrics used to provide an early warning of increasing risk exposures, making them ideal for signaling when controls (like change approval processes) are being bypassed or are ineffective due to emergency actions, which could lead to significant risk. This allows management to proactively address potential issues before they become incidents.

Concept tested: Risk reporting (KRIs)

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategies#monitoring-and-reporting

Topics

#Key Risk Indicators (KRIs)#Risk Reporting#Emergency Changes#Change Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice