CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

A security operations center (SOC) manager is reviewing their organization's risk register. They notice that many identified risks lack clear descriptions of the existing controls in place to mitigate them, or the residual risk level post-control implementation. This omission makes it difficult to prioritize remediation efforts and understand the organization's true risk posture. Which essential element of a comprehensive risk register is MOST overlooked in this situation?

  1. AControl effectiveness and residual risk
  2. BRisk owner and accountability
  3. CTarget risk level and acceptance criteria
  4. DRisk category and classification
Show answer & explanation

Correct answer: A. Control effectiveness and residual risk

A comprehensive risk register should not only list identified risks but also detail the existing controls, assess their effectiveness, and determine the residual risk level after controls are applied. Without this information, prioritizing remediation and understanding the true risk posture becomes challenging, as the current state of risk is unclear.

Why the other options are wrong

  • B. Risk owner and accountability are crucial for management, but the immediate issue is the lack of information about how risks are currently being managed.
  • C. Target risk level and acceptance criteria define the desired future state, but cannot be effectively determined or tracked without knowing the current residual risk.
  • D. Risk category and classification are important for organization, but do not address the lack of control and residual risk information.

Risk Register Completeness

A complete risk register includes detailed information for each risk, such as description, impact, likelihood, existing controls, control effectiveness, and residual risk.

  • Facilitates informed decision-making.
  • Provides a current view of the risk landscape.
  • Essential for monitoring and reporting.

Memory trick: A register is complete when it 'Covers All Controls and Residuals'.

More IT Risk Assessment questions