nerdexam
Isaca

CRISC · Question #593

An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios app

The correct answer is A. Map the granular risk scenarios to the high-level risk register items.. To ensure alignment between a high-level enterprise risk register and a more granular IT risk register, the most effective method is to explicitly map the detailed IT scenarios to the broader enterprise risk items. This mapping provides traceability and demonstrates how IT-specif

Submitted by jian89· Apr 18, 2026Governance

Question

An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios applicable to IT. Which of the following is the BEST way to ensure alignment between these two registers?

Options

  • AMap the granular risk scenarios to the high-level risk register items.
  • BList application and server vulnerabilities in the IT risk register.
  • CIdentify overlapping risk scenarios between the two registers.
  • DMaintain both high-level and granular risk scenarios in a single register.

How the community answered

(44 responses)
  • A
    77% (34)
  • B
    2% (1)
  • C
    14% (6)
  • D
    7% (3)

Why each option

To ensure alignment between a high-level enterprise risk register and a more granular IT risk register, the most effective method is to explicitly map the detailed IT scenarios to the broader enterprise risk items. This mapping provides traceability and demonstrates how IT-specific risks contribute to or are covered by the organization's overarching risk posture.

AMap the granular risk scenarios to the high-level risk register items.Correct

Mapping granular IT risk scenarios to high-level enterprise risk items explicitly links detailed IT risks to the organization's strategic risks, ensuring consistency, traceability, and demonstrating how IT contributes to enterprise-wide risk management. This process shows how lower-level risks roll up into the larger organizational risk profile.

BList application and server vulnerabilities in the IT risk register.

Listing vulnerabilities is part of populating the IT risk register, but it doesn't inherently ensure alignment with the *enterprise-wide* register's higher-level risks.

CIdentify overlapping risk scenarios between the two registers.

Identifying overlaps is a partial step, but *mapping* provides a structured and comprehensive alignment, establishing clear relationships rather than just finding commonalities.

DMaintain both high-level and granular risk scenarios in a single register.

While a single register might seem simpler, the question implies two separate registers for different levels of detail, and merging them isn't always practical or desirable for large organizations, nor does it guarantee alignment between the two distinct levels.

Concept tested: Risk register alignment and hierarchy

Source: https://www.isaca.org/resources/isaca-journal/issues/2011/volume-3/how-to-implement-an-enterprise-risk-management-erm-program

Topics

#Risk Register#Enterprise Risk Management#IT Risk Management#Risk Alignment

Community Discussion

No community discussion yet for this question.

Full CRISC Practice