CRISC · Question #598
During the creation of an organization's IT risk management program, the BEST time to identify key risk indicators (KRIs) is while:
The correct answer is C. Developing a risk monitoring process. The best time to identify Key Risk Indicators (KRIs) during the creation of an IT risk management program is while developing the risk monitoring process. KRIs are essential metrics used to track and report on changes in risk exposure over time, directly supporting the monitoring
Question
During the creation of an organization's IT risk management program, the BEST time to identify key risk indicators (KRIs) is while:
Options
- AInterviewing data owners
- BReviewing risk response plans with internal audit
- CDeveloping a risk monitoring process
- DReviewing an external risk assessment
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C77% (27)
- D14% (5)
Why each option
The best time to identify Key Risk Indicators (KRIs) during the creation of an IT risk management program is while developing the risk monitoring process. KRIs are essential metrics used to track and report on changes in risk exposure over time, directly supporting the monitoring function.
Interviewing data owners helps identify *risks* and assets, but not specifically the indicators for *monitoring* the ongoing status or changes in those risks.
Reviewing risk response plans with internal audit occurs *after* risks are identified and responses defined; KRIs are for ongoing monitoring of the effectiveness of those responses and the overall risk posture.
Key Risk Indicators (KRIs) are metrics used to provide an early signal of increasing risk exposure, making them integral to an effective risk monitoring process. Therefore, identifying KRIs is best done concurrently with or as a foundational step of developing the risk monitoring process, as they define what needs to be tracked and reported for ongoing risk awareness.
Reviewing an external risk assessment provides valuable input on potential risks, but the *identification* of specific internal KRIs is a distinct step tied to the organization's own monitoring requirements.
Concept tested: Key Risk Indicator (KRI) identification
Source: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-3/key-risk-indicators-kriss-and-key-performance-indicators-kpis
Topics
Community Discussion
No community discussion yet for this question.