CRISC Certified in Risk and Information Systems ControlGovernanceHard

A software development company is considering adopting a new agile methodology. The board is concerned that the rapid development cycles might introduce unmanaged risks. To ensure proper governance, what should the risk management team primarily focus on?

  1. AImplementing a gate-based approval process for each agile sprint.
  2. BIntegrating risk management activities directly into the agile development lifecycle.
  3. CRequiring all developers to attend a comprehensive risk management training course.
  4. DDeveloping a separate, independent risk assessment for each new software release.
Show answer & explanation

Correct answer: B. Integrating risk management activities directly into the agile development lifecycle.

For agile methodologies, traditional, separate risk processes can hinder speed. The most effective governance approach is to integrate risk management activities directly into the agile lifecycle, ensuring continuous risk identification, assessment, and mitigation without impeding agility.

Why the other options are wrong

  • A. Gate-based approvals can counteract the agility benefit and slow down development, which is contrary to the agile philosophy.
  • C. Training is beneficial but doesn't, by itself, embed risk management into the workflow; it's a supportive, not primary, action for integration.
  • D. Separate assessments for each release can be cumbersome and may not keep pace with rapid agile iterations, leading to reactive rather than proactive risk management.

Organizational Governance

The system by which an organization is directed and controlled. It encompasses the framework of authority, accountability, and oversight.

  • Ensures objectives are achieved.
  • Provides oversight for risk management.
  • Includes roles, policies, and processes.

Memory trick: Integrate risk, don't separate it from agile.

More Governance questions