nerdexam
Isaca

CRISC · Question #446

A risk practitioner has reviewed new international regulations and realizes the new regulations will affect the organization. Which of the following should be the risk practitioner's NEXT course of…

The correct answer is B. Update risk scenarios in the risk register. After identifying new regulations affecting the organization, the risk practitioner's next course of action should be to update the risk scenarios in the risk register.

Submitted by takeshi77· Apr 18, 2026IT Risk Assessment

Question

A risk practitioner has reviewed new international regulations and realizes the new regulations will affect the organization. Which of the following should be the risk practitioner's NEXT course of action?

Options

  • AConduct a peer response assessment.
  • BUpdate risk scenarios in the risk register.
  • CReevaluate the risk management program.
  • DEnsure applications are compliant.

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    78% (31)
  • C
    8% (3)
  • D
    3% (1)

Why each option

After identifying new regulations affecting the organization, the risk practitioner's next course of action should be to update the risk scenarios in the risk register.

AConduct a peer response assessment.

Conducting a peer response assessment might be useful later, but it's not the immediate next step in formalizing the risk internally.

BUpdate risk scenarios in the risk register.Correct

Once new regulations are identified as impacting the organization, the risk register needs to be updated immediately to incorporate these new compliance risks. This ensures that the organization formally acknowledges, documents, and begins to assess the potential impact and likelihood of non-compliance, which is a foundational step before determining specific mitigation actions or broader program reevaluation.

CReevaluate the risk management program.

Reevaluating the entire risk management program might be necessary eventually, but first, the specific risks introduced by the new regulations need to be documented.

DEnsure applications are compliant.

Ensuring applications are compliant is a specific mitigation action that comes after the risks have been identified, documented, and assessed in the risk register.

Concept tested: Regulatory risk incorporation into risk register

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-risk-vulnerability-management#rvm-2-perform-risk-assessments

Topics

#Risk identification#Risk register#Regulatory impact#Risk scenarios

Community Discussion

No community discussion yet for this question.

Full CRISC Practice