CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentEasy

A newly appointed CRISC professional is reviewing an organization's risk register. They notice that many entries lack clear ownership, making it difficult to track progress on risk responses. Which section of a well-maintained risk register should the CRISC professional recommend updating to address this issue?

  1. ARisk Description
  2. BRisk Owner
  3. CRisk Category
  4. DRisk Likelihood
Show answer & explanation

Correct answer: B. Risk Owner

Clear ownership is crucial for accountability and effective risk management. The 'Risk Owner' field in a risk register explicitly assigns responsibility for managing a specific risk and its associated responses.

Why the other options are wrong

  • A. The risk description explains what the risk is, but not who is responsible for it.
  • C. The risk category groups similar risks but does not assign individual accountability.
  • D. Risk likelihood assesses the probability of the risk occurring, not who is responsible for its management.

Risk Register Elements

A central repository for all identified risks, their analysis, and response plans.

  • Includes risk ID, description, owner, likelihood, impact, and response.
  • Supports ongoing monitoring and review.
  • Facilitates communication about risks.

Memory trick: The Register has IDs, Descriptions, Owners, and Plans.

More IT Risk Assessment questions