CRISC IT Risk Identification Practice Question
A manufacturing firm's risk practitioner is facilitating a workshop to identify IT risks for a new industrial control system (ICS) rollout. Operational engineers, IT staff, and a third-party integrator are present. Which of the following approaches BEST supports comprehensive IT risk identification in this setting?
⚠ Common exam trap
The trap here is equating a technical vulnerability scan with risk identification, when scans capture weaknesses rather than business-relevant risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Facilitate a structured, cross-functional workshop using techniques such as brainstorming and scenario analysis, supplemented by asset and threat information.
Cross-functional, structured workshops combine the operational, technical, and business knowledge needed to identify risks comprehensively, and supplementing them with asset and threat data grounds the discussion in evidence. Relying on a vendor, a single team's scan output, or waiting for live incidents all narrow the input or defer identification until treatment is far more costly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Postpone identification until the ICS has been in production for six months so real incidents can be observed.
Why it's wrong here
Waiting for production incidents means risks are discovered through failures rather than managed in advance, which is contrary to the purpose of risk identification. Design-stage identification allows treatment, such as network segmentation or safety interlocks, to be built in at far lower cost than retrofitting after an outage or safety event. Observation of live operations is useful for validation and monitoring, not as a substitute for proactive identification.
- ✗
Rely solely on the third-party integrator's risk assessment because they designed the ICS architecture.
Why it's wrong here
The integrator sees the technical design but lacks visibility into the firm's business processes, regulatory obligations, and internal dependencies, so its assessment will be incomplete. Outsourcing identification also removes the internal knowledge transfer needed to own and treat the risks later. A vendor's perspective is a valuable input, but using it as the sole source violates the principle that risk identification should draw on multiple informed viewpoints.
- ✗
Ask only the IT security team to complete a vulnerability scan and treat the scan output as the risk list.
Why it's wrong here
Scan results identify technical weaknesses, not risks expressed in business terms, and they miss threats that have no technical signature, such as insider error or process gaps. Restricting input to one team also excludes the operational engineers who understand how the ICS is actually used. A scan is one identification technique among many and cannot stand in for a facilitated, cross-functional risk identification effort.
- ✓
Facilitate a structured, cross-functional workshop using techniques such as brainstorming and scenario analysis, supplemented by asset and threat information.
Why this is correct
Bringing operations, IT, and the integrator together surfaces technical, process, and business perspectives that no single group holds. Structured techniques such as scenario analysis and brainstorming, informed by asset inventories and threat intelligence, produce risks expressed in business terms and build shared ownership. ISACA guidance favors such facilitated approaches because they capture tacit knowledge and reduce the blind spots that siloed identification creates.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.