nerdexam
Isaca

CRISC · Question #388

A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:

The correct answer is B. validating the risk scenarios. Involving business stakeholders for validating bottom-up IT risk scenarios is most important to ensure the scenarios are realistic, relevant, and accurately reflect potential impacts on business objectives.

Submitted by cyberguy42· Apr 18, 2026IT Risk Assessment

Question

A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:

Options

  • Aupdating the risk register.
  • Bvalidating the risk scenarios.
  • Cdocumenting the risk scenarios.
  • Didentifying risk mitigation controls.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    84% (31)
  • C
    5% (2)
  • D
    8% (3)

Why each option

Involving business stakeholders for validating bottom-up IT risk scenarios is most important to ensure the scenarios are realistic, relevant, and accurately reflect potential impacts on business objectives.

Aupdating the risk register.

Updating the risk register is an ongoing process that might involve stakeholders but is not the most critical point for their input on scenario development.

Bvalidating the risk scenarios.Correct

When developing bottom-up IT risk scenarios, it is most important to involve business stakeholders during the validation phase. Business stakeholders possess critical knowledge of operational processes, strategic objectives, and the real-world impact of IT failures or vulnerabilities on the business. Their validation ensures that the scenarios are realistic, relevant to business objectives, and that the potential consequences are accurately understood and prioritized from a business perspective.

Cdocumenting the risk scenarios.

Documenting the risk scenarios is primarily a task for the risk practitioner, although it incorporates input from stakeholders; the validation step ensures accuracy before final documentation.

Didentifying risk mitigation controls.

Identifying risk mitigation controls comes after the scenarios have been defined and validated, making validation a more foundational step for stakeholder involvement in scenario development.

Concept tested: Stakeholder involvement in risk scenario validation

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-management-decision-support

Topics

#IT Risk Assessment#Risk Scenarios#Stakeholder Engagement#Risk Validation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice