CRISC · Question #503
Which of the following is the MOST important reason for a risk practitioner to continuously monitor a critical security transformation program?
The correct answer is C. To ensure program risk events are mitigated in a timely manner. The most important reason for continuous monitoring of a critical security transformation program is to ensure that program risk events are identified and mitigated promptly. This proactive approach prevents risks from escalating and jeopardizing the program's success.
Question
Which of the following is the MOST important reason for a risk practitioner to continuously monitor a critical security transformation program?
Options
- ATo validate the quality of defined deliverables for the program
- BTo detect increases in program costs
- CTo ensure program risk events are mitigated in a timely manner
- DTo provide timely reporting to the governance steering committee
How the community answered
(41 responses)- A10% (4)
- B15% (6)
- C71% (29)
- D5% (2)
Why each option
The most important reason for continuous monitoring of a critical security transformation program is to ensure that program risk events are identified and mitigated promptly. This proactive approach prevents risks from escalating and jeopardizing the program's success.
Validating the quality of deliverables is part of program management and quality assurance, but it's secondary to the direct management of risks that could prevent *any* deliverables from being achieved.
Detecting increases in program costs is an important aspect of financial control, but it's a symptom that often stems from unmanaged risks, making risk mitigation more fundamental.
Continuous monitoring allows a risk practitioner to identify new or changing risks, track the effectiveness of existing controls, and ensure that any emerging program risk events are addressed and mitigated without delay. This proactive risk management is critical for the successful completion of a security transformation program, as unmitigated risks can lead to significant delays, budget overruns, or failure to meet security objectives.
Providing timely reporting to the governance steering committee is a communication function of program management, but the *reason* for monitoring is to *enable* accurate and timely reporting on the program's health, particularly its risks.
Concept tested: Continuous risk monitoring in programs
Source: https://csrc.nist.gov/glossary/term/continuous_monitoring
Topics
Community Discussion
No community discussion yet for this question.