CRISC · Question #275
Which of the following is MOST important to ensure when reviewing an organization's risk register?
The correct answer is A. Risk ownership is recorded.. When reviewing an organization's risk register, it is most important to ensure that risk ownership is recorded to assign clear responsibility for management and mitigation.
Question
Which of the following is MOST important to ensure when reviewing an organization's risk register?
Options
- ARisk ownership is recorded.
- BVulnerabilities have separate entries.
- CControl ownership is recorded.
- DResidual risk is less than inherent risk.
How the community answered
(34 responses)- A79% (27)
- B12% (4)
- C3% (1)
- D6% (2)
Why each option
When reviewing an organization's risk register, it is most important to ensure that risk ownership is recorded to assign clear responsibility for management and mitigation.
Assigning risk ownership is crucial because it designates a specific individual or entity responsible for monitoring, managing, and responding to each identified risk. Without clear ownership, risks can be overlooked or mishandled, undermining the entire risk management process and accountability.
While vulnerabilities are components of risk, ensuring they have separate entries in the risk register isn't necessarily the *most* important aspect; risks are often broader concepts than individual vulnerabilities.
Control ownership is important for accountability in control implementation, but it is secondary to risk ownership, which defines who is responsible for the overall risk itself.
Residual risk *should* ideally be less than inherent risk, indicating effective controls, but this is an outcome or state to be achieved, not a foundational element that must be 'ensured' in the register review itself, like ownership.
Concept tested: Risk register components, risk ownership
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.