Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A retail company's risk practitioner is reviewing how risks flow between the enterprise risk management function and the IT risk function. The CISO argues that IT risks should be reported only within IT, while the CRO wants material IT risks elevated to the enterprise register. Which CRISC principle BEST resolves this disagreement?

⚠ Common exam trap

The trap here is treating IT risk as a separate discipline owned solely by security, when CRISC frames it as an integral part of enterprise risk that must be reported at the business level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IT risk is a subset of enterprise risk and material IT risks should be integrated into enterprise risk reporting.

The correct principle is that IT risk is a subset of enterprise risk and material IT risks belong in enterprise reporting. This ensures business leadership sees how technology exposures affect objectives and can allocate resources and set tolerance accordingly. IT still performs the technical analysis, but the results flow upward so governance and strategy reflect the full risk landscape rather than a fragmented view.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both registers should be maintained independently and reconciled only during the annual external audit.

    Why it's wrong here

    Independent registers reconciled once a year create blind spots and lag time. Material IT risks can evolve quickly, and annual reconciliation means leadership may operate for months unaware of exposures affecting strategy. Continuous integration and consistent escalation criteria are needed so the enterprise register reflects current IT risk reality in a timely manner.

  • ✓

    IT risk is a subset of enterprise risk and material IT risks should be integrated into enterprise risk reporting.

    Why this is correct

    CRISC treats IT risk as a component of enterprise risk, not a separate silo. Risks that threaten business objectives must flow into enterprise reporting so leadership sees the full exposure picture. Keeping material IT risks inside IT hides their business impact from the board and breaks the linkage between technology failures and strategic outcomes, which undermines integrated risk management.

  • ✗

    IT risks should remain under the CISO because only technical staff can interpret their likelihood.

    Why it's wrong here

    Technical interpretation is valuable for analysis, but it does not justify isolating IT risk from enterprise reporting. Business leaders own the objectives at risk and must see material exposures to make informed decisions. Retaining all IT risk within the security function prevents the board from understanding aggregate exposure and contradicts the principle that IT risk is part of enterprise risk.

  • ✗

    The CRO should take over all IT risk analysis to ensure consistent methodology across the enterprise.

    Why it's wrong here

    Centralizing all IT risk analysis in the enterprise risk function strips the technical context needed to assess likelihood and control effectiveness. The enterprise function sets methodology and aggregation standards, while IT and business subject matter experts contribute the technical detail. Removing IT from its own risk analysis produces inaccurate assessments and weak ownership.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.