CRISC · Question #279
Which of the following should be considered FIRST when creating a comprehensive IT risk register?
The correct answer is C. Risk appetite. When creating a comprehensive IT risk register, the organization's risk appetite should be considered first, as it sets the boundaries for acceptable risk.
Question
Which of the following should be considered FIRST when creating a comprehensive IT risk register?
Options
- ARisk management budget
- BRisk mitigation policies
- CRisk appetite
- DRisk analysis techniques
How the community answered
(34 responses)- A6% (2)
- C91% (31)
- D3% (1)
Why each option
When creating a comprehensive IT risk register, the organization's risk appetite should be considered first, as it sets the boundaries for acceptable risk.
The risk management budget is a practical constraint for mitigation, but the *type* and *level* of risk to be managed (informed by appetite) must be understood before allocating funds.
Risk mitigation policies are developed *after* risks are identified and assessed against the risk appetite, to determine how to treat them.
Risk appetite defines the amount and type of risk an organization is willing to accept to achieve its objectives. It is the foundational consideration because it guides which risks are prioritized, how they are assessed, and what level of mitigation is deemed appropriate for inclusion and management within the risk register.
Risk analysis techniques are tools used to assess risks, but what risks to analyze and to what depth is determined by the organization's overarching risk appetite.
Concept tested: Risk management fundamentals, risk appetite definition
Source: https://csrc.nist.gov/publications/detail/sp/800-39/final
Topics
Community Discussion
No community discussion yet for this question.