CRISC · Question #29
Which of the following would MOST likely require a risk practitioner to update the risk register?
The correct answer is C. Completion of a project for implementing a new control. The completion of a project for implementing a new control is the event most likely requiring a risk practitioner to update the risk register. This action directly changes the organization's risk posture by introducing a mitigation, necessitating a review and update of associated
Question
Which of the following would MOST likely require a risk practitioner to update the risk register?
Options
- AAn alert being reported by the security operations center.
- BDevelopment of a project schedule for implementing a risk response
- CCompletion of a project for implementing a new control
- DEngagement of a third party to conduct a vulnerability scan
How the community answered
(27 responses)- A4% (1)
- B4% (1)
- C81% (22)
- D11% (3)
Why each option
The completion of a project for implementing a new control is the event most likely requiring a risk practitioner to update the risk register. This action directly changes the organization's risk posture by introducing a mitigation, necessitating a review and update of associated risk statuses and residual risk levels.
An alert from a security operations center (SOC) typically indicates a potential incident or anomalous activity, which might trigger an investigation, but it doesn't automatically require an update to the *risk register* itself unless it reveals a previously unknown risk or a significant change in an existing one.
The development of a project schedule for a risk response is a planning activity; the actual *implementation* (completion) is what changes the risk posture and requires the register update.
The completion of a project that implements a new control directly changes the organization's risk posture by mitigating an existing risk or addressing a vulnerability. This significant event necessitates an update to the risk register to reflect the implemented control, reassess the residual risk, and potentially change the status of the associated risk from "open" or "in progress" to "mitigated" or "monitored."
Engaging a third party for a vulnerability scan is an assessment activity designed to *identify* vulnerabilities, which may *lead* to identifying new risks or updating existing ones, but the *engagement itself* doesn't directly alter the risk posture. The *findings* of the scan, once analyzed, might lead to an update.
Concept tested: Risk register update triggers
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.