nerdexam
Isaca

CRISC · Question #279

Which of the following should be considered FIRST when creating a comprehensive IT risk register?

The correct answer is C. Risk appetite. When creating a comprehensive IT risk register, the organization's risk appetite should be considered first, as it sets the boundaries for acceptable risk.

Submitted by takeshi77· Apr 18, 2026Governance

Question

Which of the following should be considered FIRST when creating a comprehensive IT risk register?

Options

  • ARisk management budget
  • BRisk mitigation policies
  • CRisk appetite
  • DRisk analysis techniques

How the community answered

(34 responses)
  • A
    6% (2)
  • C
    91% (31)
  • D
    3% (1)

Why each option

When creating a comprehensive IT risk register, the organization's risk appetite should be considered first, as it sets the boundaries for acceptable risk.

ARisk management budget

The risk management budget is a practical constraint for mitigation, but the *type* and *level* of risk to be managed (informed by appetite) must be understood before allocating funds.

BRisk mitigation policies

Risk mitigation policies are developed *after* risks are identified and assessed against the risk appetite, to determine how to treat them.

CRisk appetiteCorrect

Risk appetite defines the amount and type of risk an organization is willing to accept to achieve its objectives. It is the foundational consideration because it guides which risks are prioritized, how they are assessed, and what level of mitigation is deemed appropriate for inclusion and management within the risk register.

DRisk analysis techniques

Risk analysis techniques are tools used to assess risks, but what risks to analyze and to what depth is determined by the organization's overarching risk appetite.

Concept tested: Risk management fundamentals, risk appetite definition

Source: https://csrc.nist.gov/publications/detail/sp/800-39/final

Topics

#Risk Register#Risk Appetite#IT Risk Management#Risk Management Process

Community Discussion

No community discussion yet for this question.

Full CRISC Practice