nerdexam
Isaca

CRISC · Question #365

Which of the following is the MOST important reason to restrict access to the risk register on a need- to-know basis?

The correct answer is A. It contains vulnerabilities and threats.. Restricting access to the risk register on a need-to-know basis is most important because it contains sensitive information about an organization's identified vulnerabilities and threats.

Submitted by tarun92· Apr 18, 2026Information Technology and Security

Question

Which of the following is the MOST important reason to restrict access to the risk register on a need- to-know basis?

Options

  • AIt contains vulnerabilities and threats.
  • BThe risk methodology is intellectual property.
  • CContents may be used as auditable findings.
  • DRisk scenarios may be misinterpreted.

How the community answered

(14 responses)
  • A
    93% (13)
  • B
    7% (1)

Why each option

Restricting access to the risk register on a need-to-know basis is most important because it contains sensitive information about an organization's identified vulnerabilities and threats.

AIt contains vulnerabilities and threats.Correct

The risk register is a critical document that often details an organization's specific vulnerabilities, potential threats, and the likelihood and impact of these risks. Unauthorized access to this information could provide attackers with a roadmap for exploitation, making it essential to protect it on a need-to-know basis.

BThe risk methodology is intellectual property.

While the risk methodology might be proprietary, it's generally less sensitive than the actual list of vulnerabilities and threats, and protecting the methodology itself is not the most important reason for restricted access to the register's contents.

CContents may be used as auditable findings.

Contents being used as auditable findings is a consequence of the risk register's existence and purpose, not the primary reason to restrict access for security.

DRisk scenarios may be misinterpreted.

While misinterpretation of risk scenarios is possible, it is a concern related to communication and training, not the paramount reason for restricting access from a security perspective.

Concept tested: Confidentiality of risk information

Topics

#Risk Register Management#Access Control#Information Security#Data Confidentiality

Community Discussion

No community discussion yet for this question.

Full CRISC Practice