CRISC Information Technology and Security Practice Question
A risk manager is designing an IT risk management program. Which document should serve as the primary source for defining the organization's approach to risk assessment, treatment, and reporting?
⚠ Common exam trap
Watch out — candidates often confuse the risk register (a tactical tool) with the risk management policy (a strategic governance document), mistakenly thinking the register defines the process rather than just recording the outputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk management policy
The risk management policy is the authoritative document that establishes the organization's overall approach to risk management, including the principles, roles, responsibilities, and processes for risk assessment, treatment, and reporting. It sets the governance framework and mandates how risk activities must be conducted across the IT environment, ensuring consistency and alignment with business objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT strategy
Why it's wrong here
IT strategy focuses on achieving business goals through IT, not risk management methodology.
- ✓
Risk management policy
Why this is correct
Correct. The risk management policy defines the approach to risk management.
- ✗
Business continuity plan
Why it's wrong here
This plan addresses continuity after a disruption, not the overall risk management approach.
- ✗
Risk register
Why it's wrong here
The risk register is a repository of identified risks, not a policy document.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.