CRISC · Question #406
A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?
The correct answer is B. Determine whether risk responses still effectively address risk.. When outsourcing IT functions following a departmental restructure, IT control owners should determine if existing risk responses remain effective in addressing the changed risk landscape.
Question
A large organization recently restructured the IT department and has decided to outsource certain functions. What action should the control owners in the IT department take?
Options
- AConduct risk classification for associated IT controls.
- BDetermine whether risk responses still effectively address risk.
- CPerform vulnerability and threat assessments.
- DAnalyze and update IT control assessments.
How the community answered
(31 responses)- A10% (3)
- B61% (19)
- C23% (7)
- D6% (2)
Why each option
When outsourcing IT functions following a departmental restructure, IT control owners should determine if existing risk responses remain effective in addressing the changed risk landscape.
While risk classification might be part of a broader risk assessment, the immediate and most critical action for control owners is to review the *effectiveness* of existing responses in the new outsourcing context.
Outsourcing introduces new risks (e.g., third-party risk, vendor lock-in, data sovereignty) and can significantly alter the effectiveness of existing internal controls and risk responses. Control owners must reassess whether the current risk responses, designed for internal operations, are still adequate or if they need to be adapted or new ones developed for the outsourced functions.
Performing vulnerability and threat assessments is a general risk activity, but the specific immediate action following outsourcing for control owners is to check if *their controls* are still working for *their risks*.
Analyzing and updating IT control assessments would be a subsequent step *after* determining if existing risk responses are still effective, as the assessment needs to reflect the current effectiveness post-outsourcing.
Concept tested: Post-restructure risk response review
Topics
Community Discussion
No community discussion yet for this question.