Courseiva

CRISC Information Technology and Security Practice Question

A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?

⚠ Common exam trap

Watch out — candidates often confuse the risk register (a tactical tool) with the risk management policy (a strategic governance document), mistakenly thinking the register defines the process rather than just recording the outputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk management policy

The risk management policy is the authoritative document that establishes the organization's overall approach to risk management, including the principles, roles, responsibilities, and processes for risk assessment, treatment, and reporting. It sets the governance framework and mandates how risk activities must be conducted across the IT environment, ensuring consistency and alignment with business objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IT strategy

    Why it's wrong here

    IT strategy sets technology direction and investment priorities, not risk assessment criteria, treatment options or reporting lines. It is tempting because risk management must align with strategic objectives, and IT strategy would be the correct source when determining which initiatives the risk programme must support.

  • ✓

    Risk management policy

    Why this is correct

    A risk management policy is the governing document that mandates the organization's approach to risk assessment, treatment, and reporting, satisfying the stem's requirement for a primary source. It establishes authority, scope, and responsibilities, unlike frameworks or procedures, which support implementation rather than define the overarching programme.

  • ✗

    Business continuity plan

    Why it's wrong here

    A business continuity plan documents recovery strategies and procedures for disruptive events; it does not define risk assessment, treatment or reporting methodology. It is tempting because it is a governance document addressing risk, and would be correct when specifying how the organisation resumes critical operations after an incident.

  • ✗

    Risk register

    Why it's wrong here

    A risk register records identified risks, owners, scores and treatment status; it does not define methodology. It is tempting because it is the central artefact of an operational risk programme, and would be the right source when retrieving the current status of a specific logged risk.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.