CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A security operations center (SOC) manager is reviewing their organization's risk register. They find an entry: 'Risk ID: R-015, Risk Description: Unauthorized access to internal network, Likelihood: High, Impact: Critical, Risk Owner: IT Operations.' The manager notes that there are no specific mitigation steps or controls documented. What is the MOST critical missing element for effective risk management of R-015?

  1. AResidual Risk Level
  2. BDate of Last Review
  3. CRisk Category
  4. DRisk Response Plan
Show answer & explanation

Correct answer: D. Risk Response Plan

While other elements are useful, a 'Risk Response Plan' (specifically, mitigation steps or controls in this case) is the most critical missing element for actually managing a 'High' likelihood, 'Critical' impact risk. Without a plan, the risk cannot be effectively addressed.

Why the other options are wrong

  • A. Residual risk level can only be determined *after* a response plan is in place and implemented.
  • B. The date of last review is important for governance but doesn't provide the actual steps to manage the risk.
  • C. Risk category helps with organization but doesn't directly address how to manage the risk.

Risk Register Completeness

Ensuring all necessary information for comprehensive risk management is documented in the risk register.

  • Includes identification, analysis, and response details.
  • Supports monitoring and reporting.
  • Facilitates informed decision-making.

Memory trick: Register Details: ID, Describe, Own, Rate, Respond, Track.

More IT Risk Assessment questions