nerdexam
Isaca

CRISC · Question #328

What should a risk practitioner do FIRST when a shadow IT application is identified in a business owner's business impact analysis (BIA)?

The correct answer is B. Determine the business purpose of the application. When shadow IT is identified, the risk practitioner's initial step should be to understand its business purpose to assess its criticality, risks, and potential value before taking any other action.

Submitted by mike_84· Apr 18, 2026IT Risk Assessment

Question

What should a risk practitioner do FIRST when a shadow IT application is identified in a business owner's business impact analysis (BIA)?

Options

  • AInclude the application in the business continuity plan (BCP).
  • BDetermine the business purpose of the application.
  • CSegregate the application from the network.
  • DReport the finding to management.

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    79% (27)
  • C
    6% (2)
  • D
    3% (1)

Why each option

When shadow IT is identified, the risk practitioner's initial step should be to understand its business purpose to assess its criticality, risks, and potential value before taking any other action.

AInclude the application in the business continuity plan (BCP).

Including the application in the BCP prematurely, without understanding its full scope and risk profile, could legitimize an unvetted system.

BDetermine the business purpose of the application.Correct

Before any other action, understanding the business purpose of the shadow IT application is critical. This initial step allows the risk practitioner to evaluate its necessity, criticality to operations, data sensitivity, and potential risks, which then informs subsequent decisions regarding its management, integration, or mitigation.

CSegregate the application from the network.

Segregating the application from the network immediately might disrupt critical business operations if its purpose is not understood and necessary.

DReport the finding to management.

Reporting the finding to management is important but should follow an initial understanding of the application's business context, to provide an informed report.

Concept tested: Shadow IT risk management initial response

Source: https://www.isaca.org/resources/isaca-journal/issues/2020/volume-5/shadow-it-risk-or-reward

Topics

#Shadow IT#Risk identification#Business Impact Analysis (BIA)#Risk assessment process

Community Discussion

No community discussion yet for this question.

Full CRISC Practice