CRISC · Question #593
An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios app
The correct answer is A. Map the granular risk scenarios to the high-level risk register items.. To ensure alignment between a high-level enterprise risk register and a more granular IT risk register, the most effective method is to explicitly map the detailed IT scenarios to the broader enterprise risk items. This mapping provides traceability and demonstrates how IT-specif
Question
An organization has established a single enterprise-wide risk register that records high-level risk scenarios. The IT risk department has created its own register to record more granular scenarios applicable to IT. Which of the following is the BEST way to ensure alignment between these two registers?
Options
- AMap the granular risk scenarios to the high-level risk register items.
- BList application and server vulnerabilities in the IT risk register.
- CIdentify overlapping risk scenarios between the two registers.
- DMaintain both high-level and granular risk scenarios in a single register.
How the community answered
(44 responses)- A77% (34)
- B2% (1)
- C14% (6)
- D7% (3)
Why each option
To ensure alignment between a high-level enterprise risk register and a more granular IT risk register, the most effective method is to explicitly map the detailed IT scenarios to the broader enterprise risk items. This mapping provides traceability and demonstrates how IT-specific risks contribute to or are covered by the organization's overarching risk posture.
Mapping granular IT risk scenarios to high-level enterprise risk items explicitly links detailed IT risks to the organization's strategic risks, ensuring consistency, traceability, and demonstrating how IT contributes to enterprise-wide risk management. This process shows how lower-level risks roll up into the larger organizational risk profile.
Listing vulnerabilities is part of populating the IT risk register, but it doesn't inherently ensure alignment with the *enterprise-wide* register's higher-level risks.
Identifying overlaps is a partial step, but *mapping* provides a structured and comprehensive alignment, establishing clear relationships rather than just finding commonalities.
While a single register might seem simpler, the question implies two separate registers for different levels of detail, and merging them isn't always practical or desirable for large organizations, nor does it guarantee alignment between the two distinct levels.
Concept tested: Risk register alignment and hierarchy
Source: https://www.isaca.org/resources/isaca-journal/issues/2011/volume-3/how-to-implement-an-enterprise-risk-management-erm-program
Topics
Community Discussion
No community discussion yet for this question.