nerdexam
Isaca

CRISC · Question #29

Which of the following would MOST likely require a risk practitioner to update the risk register?

The correct answer is C. Completion of a project for implementing a new control. The completion of a project for implementing a new control is the event most likely requiring a risk practitioner to update the risk register. This action directly changes the organization's risk posture by introducing a mitigation, necessitating a review and update of associated

Submitted by akirajp· Apr 18, 2026Risk Response and Reporting

Question

Which of the following would MOST likely require a risk practitioner to update the risk register?

Options

  • AAn alert being reported by the security operations center.
  • BDevelopment of a project schedule for implementing a risk response
  • CCompletion of a project for implementing a new control
  • DEngagement of a third party to conduct a vulnerability scan

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    81% (22)
  • D
    11% (3)

Why each option

The completion of a project for implementing a new control is the event most likely requiring a risk practitioner to update the risk register. This action directly changes the organization's risk posture by introducing a mitigation, necessitating a review and update of associated risk statuses and residual risk levels.

AAn alert being reported by the security operations center.

An alert from a security operations center (SOC) typically indicates a potential incident or anomalous activity, which might trigger an investigation, but it doesn't automatically require an update to the *risk register* itself unless it reveals a previously unknown risk or a significant change in an existing one.

BDevelopment of a project schedule for implementing a risk response

The development of a project schedule for a risk response is a planning activity; the actual *implementation* (completion) is what changes the risk posture and requires the register update.

CCompletion of a project for implementing a new controlCorrect

The completion of a project that implements a new control directly changes the organization's risk posture by mitigating an existing risk or addressing a vulnerability. This significant event necessitates an update to the risk register to reflect the implemented control, reassess the residual risk, and potentially change the status of the associated risk from "open" or "in progress" to "mitigated" or "monitored."

DEngagement of a third party to conduct a vulnerability scan

Engaging a third party for a vulnerability scan is an assessment activity designed to *identify* vulnerabilities, which may *lead* to identifying new risks or updating existing ones, but the *engagement itself* doesn't directly alter the risk posture. The *findings* of the scan, once analyzed, might lead to an update.

Concept tested: Risk register update triggers

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf

Topics

#Risk Register#Risk Response#Control Implementation#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CRISC Practice