CRISC · Question #23
When of the following standard operating procedure (SOP) statements BEST illustrates appropriate risk register maintenance?
The correct answer is C. Remove risk only following a significant change in the risk environment. Appropriate risk register maintenance involves updating entries when there is a significant change in the risk environment, rather than removing them immediately upon mitigation or acceptance. Risks, even if mitigated or accepted, should remain visible in the register to reflect
Question
When of the following standard operating procedure (SOP) statements BEST illustrates appropriate risk register maintenance?
Options
- ARemove risk that has been mitigated by third-party transfer
- BRemove risk that management has decided to accept
- CRemove risk only following a significant change in the risk environment
- DRemove risk when mitigation results in residual risk within tolerance levels
How the community answered
(26 responses)- A15% (4)
- B4% (1)
- C73% (19)
- D8% (2)
Why each option
Appropriate risk register maintenance involves updating entries when there is a significant change in the risk environment, rather than removing them immediately upon mitigation or acceptance. Risks, even if mitigated or accepted, should remain visible in the register to reflect the organization's complete risk landscape over time.
When risk is mitigated by third-party transfer (e.g., insurance), the risk itself isn't *removed*; rather, the responsibility and financial impact are shifted, and this change should be documented, not deleted.
When management accepts a risk, it means they acknowledge its existence and potential impact without further mitigation, and the risk still exists and should remain in the register with its acceptance status noted.
Risk register maintenance should reflect the dynamic nature of risks; therefore, removing risks only after a significant change in the environment, such as a major system overhaul or new threat landscape, ensures the register remains relevant and historically accurate. Mitigation, acceptance, or transfer typically changes the *status* or *level* of the risk but the event itself often remains a potential threat that should be documented and reviewed periodically, rather than outright removed.
While successful mitigation reduces residual risk, the original risk and its current state should still be tracked; removing it entirely would erase the history of the risk and the effort to mitigate it, which is valuable for future analysis and audits.
Concept tested: Risk register maintenance best practices
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.