CRISC · Question #374
Which of the following is the PRIMARY reason to ensure policies and standards are properly documented within the risk management process?
The correct answer is B. It establishes a means for senior management to formally approve risk practices. Documenting policies and standards within risk management primarily provides a formal mechanism for senior management to review and approve the organization's risk practices, ensuring accountability and alignment.
Question
Which of the following is the PRIMARY reason to ensure policies and standards are properly documented within the risk management process?
Options
- AIt facilitates the use of a framework for risk management.
- BIt establishes a means for senior management to formally approve risk practices.
- CIt encourages risk-based decision making for stakeholders.
- DIt provides a basis for benchmarking against industry standards.
How the community answered
(24 responses)- A4% (1)
- B75% (18)
- C13% (3)
- D8% (2)
Why each option
Documenting policies and standards within risk management primarily provides a formal mechanism for senior management to review and approve the organization's risk practices, ensuring accountability and alignment.
While documented policies can align with frameworks, their primary purpose in documentation isn't just facilitation, but rather formalization and approval.
Documenting policies and standards is essential because it creates a formal record that senior management can review, understand, and then formally approve, thereby establishing official organizational commitment and accountability to the defined risk management practices. This formal approval signifies that the practices are endorsed by leadership and are mandatory for the organization.
Documented policies help guide decision-making, but the *primary reason for documentation itself* is to make them official and subject to approval.
Benchmarking might utilize documented policies for comparison, but the initial and primary reason for documentation is internal formalization and approval, not external comparison.
Concept tested: Importance of documenting risk policies
Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001
Topics
Community Discussion
No community discussion yet for this question.