Which of the following should be the FIRST course of action if the risk associated with a new technology is found to be increasing?
Correct Answer: B
A risk action plan is a document that outlines the actions to be taken to mitigate or avoid a risk. A risk action plan should be revised when the risk associated with a new technology is found to be increasing, as this indicates that the current plan is not effective or sufficient. Revising the risk action plan can help identify the root causes of the risk increase, evaluate the effectiveness of current controls, and implement additional or alternative controls as needed. Re-evaluating current controls, escalating the risk to senior management, and implementing additional controls are possible steps in the revision process, but they are not the first course of action. The first course of action should be to update the risk action plan to reflect the current risk situation and the appropriate risk response.
CRISC Exam Question 137
Which of the following is MOST important to review when determining whether a potential IT service provider's control environment is effective?
Correct Answer: A
The MOST important thing to review when determining whether a potential IT service provider's control environment is effective is an independent audit report, because it provides an objective and reliable assessment of the service provider's controls and compliance with standards and regulations. The other options are not as important as an independent audit report, because: Option B: Control self-assessment is a subjective and voluntary process that may not reflect the actual effectiveness of the service provider's controls. Option C: This option is incomplete and irrelevant to the question. Option D: Service level agreements (SLAs) are contractual agreements that specify the expected performance and availability of the service provider, but they do not necessarily indicate the effectiveness of the service provider's controls. References = Risk and Information Systems Control Study Manual, 7th Edition, ISACA, 2020, p. 195.
CRISC Exam Question 138
What is the GREATEST concern with maintaining decentralized risk registers instead of a consolidated risk register?
Correct Answer: A
A risk register is a tool that records and tracks the identified risks, their causes, impacts, likelihood, responses, and owners. A decentralized risk register is maintained by each business unit or function, while a consolidated risk register is maintained at the enterprise level. The greatest concern with maintaining decentralized risk registers instead of a consolidated risk register is that the aggregated risk may exceed the enterprise's risk appetite and tolerance. Risk appetite is the amount and type of risk that an enterprise is willing to accept in pursuit of its objectives, while risk tolerance is the acceptable level of variation around the objectives. If the risk registers are not consolidated, the enterprise may not have a holistic view of its risk profile and may not be able to prioritize and allocate resources effectively. The other options are also concerns, but they are not as significant as the potential misalignment between the aggregated risk and the enterprise's risk appetite and tolerance. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 1, Section 1.2.2.2, pp. 21-22.
CRISC Exam Question 139
Which of the following is the BEST course of action for a system administrator who suspects a colleague may be intentionally weakening a system's validation controls in order to pass through fraudulent transactions?
Correct Answer: B
The best course of action for a system administrator who suspects a colleague may be intentionally weakening a system's validation controls in order to pass through fraudulent transactions is B. Share the concern through a whistleblower communication channel1 According to the CRISC Review Manual, a whistleblower communication channel is a mechanism that allows employees to report suspected fraud or unethical behavior without fear of retaliation or reprisal. A whistleblower communication channel is part of an effective fraud detection and prevention framework, and it helps to promote a culture of integrity and accountability within the organization2 The other options are not as effective or appropriate as sharing the concern through a whistleblower communication channel, because: *A. Implementing compensating controls to deter fraud attempts may not address the root cause of the problem, and it may also create additional complexity and cost for the system. Moreover, it may not prevent the colleague from finding other ways to bypass the controls or collude with external parties. *C. Monitoring the activity to collect evidence may expose the system administrator to legal or ethical risks, especially if the monitoring is done without proper authorization or due process. It may also delay the reporting and resolution of the issue, and potentially allow more fraudulent transactions to occur. *D. Determining whether the system environment has flaws that may motivate fraud attempts may be useful for understanding the context and the factors that contribute to the fraud risk, but it does not address the immediate concern of reporting the suspected fraud. It may also imply that the system administrator is trying to justify or rationalize the colleague's behavior, rather than holding them accountable. 1: CRISC Review Questions, Answers & Explanations Database, Question ID: 100002 2: CRISC Review Manual, 7th Edition, page 224
CRISC Exam Question 140
A risk practitioner is advising management on how to update the IT policy framework to account for the organization s cloud usage. Which of the following should be the FIRST step in this process?
Correct Answer: C
Updating IT Policy Framework for Cloud Usage: Gap Analysis: The first step in updating the IT policy framework is to conduct a gap analysis to identify discrepancies between the current state and the desired target framework for cloud usage. Assessment of Current State: This involves reviewing existing policies, controls, and practices related to cloud usage to understand current capabilities and limitations. Target Framework Definition: Define the desired state based on industry best practices, regulatory requirements, and organizational objectives. Importance of Gap Analysis: Focused Improvements: Identifying gaps allows the organization to focus on specific areas that need enhancement to align with best practices and compliance requirements. Resource Allocation: Helps in allocating resources effectively to address the most critical gaps first. Comparison with Other Options: Consult with Industry Peers: Useful for gathering insights but should follow the gap analysis to ensure relevance to the organization's specific context. Evaluate Adherence to Existing Policies: Part of the gap analysis but not the initial step. Adopt Industry-leading Framework: Important for long-term strategy but should be based on identified gaps. Best Practices: Comprehensive Review: Conduct a thorough review of existing policies and compare them with industry standards. Stakeholder Involvement: Engage relevant stakeholders in the gap analysis to ensure all perspectives are considered. References: CRISC Review Manual: Emphasizes the importance of gap analysis in aligning IT policies with cloud computing frameworks and best practices . ISACA Guidelines: Recommend conducting gap analysis as a foundational step in updating IT policy frameworks to ensure comprehensive and effective cloud governance .