CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

An IT department is implementing a new customer relationship management (CRM) system. During the risk analysis, the team identifies a potential risk: 'Loss of customer data due to insufficient access controls'. The inherent risk is determined to be 'High'. After implementing granular role-based access controls and conducting user training, the residual risk is assessed as 'Medium'. What is the MOST critical next step for the risk manager regarding this specific risk?

  1. ATransfer the residual risk to a third-party cybersecurity insurance provider.
  2. BDocument the residual risk in the risk register and close the risk.
  3. CIdentify additional controls to further reduce the residual risk to 'Low'.
  4. DSeek management approval to accept the 'Medium' residual risk.
Show answer & explanation

Correct answer: D. Seek management approval to accept the 'Medium' residual risk.

After implementing controls and assessing residual risk, the most critical next step is to seek management approval for the remaining 'Medium' residual risk. This ensures that the organization's leadership is aware of and formally accepts the current level of risk, aligning with the organization's risk appetite.

Why the other options are wrong

  • A. Transferring the risk might be a future option, but it's not the immediate, most critical step after assessing residual risk and before formal acceptance.
  • B. Documenting is necessary but closing the risk without management acceptance is premature, especially if 'Medium' is still above appetite.
  • C. Identifying additional controls might be an option if 'Medium' is still too high, but formal acceptance of the current state is the immediate governance step.

Residual Risk Acceptance

The formal process where management acknowledges and agrees to bear the level of risk that remains after implementing risk treatment measures.

  • Crucial governance step in risk management.
  • Ensures alignment with organizational risk appetite.
  • Requires clear communication and documentation.

Memory trick: After mitigating, the boss must sign off on what's left.

More IT Risk Assessment questions