Courseiva

CRISC Information Technology and Security Practice Question

A risk manager is integrating risk management with IT governance. Which of the following are key elements of an IT risk management programme design? (Choose TWO.)

⚠ Common exam trap

The trap is selecting operational security documents (IR plan, BCP, vendor policy) as risk programme design elements — CRISC tests whether you distinguish foundational risk management components (methodology, register) from adjacent operational plans that consume risk outputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk assessment methodology

Option A (Risk assessment methodology) is correct because an IT risk management programme must define a consistent, repeatable approach for identifying, analyzing, and evaluating risks — including likelihood, impact, and risk criteria — so that risks can be prioritized and treated consistently across the enterprise. Option E (Risk register) is correct because it is the core record that captures identified risks, their owners, ratings, treatment decisions, and status, enabling ongoing monitoring and reporting that links IT risk to governance objectives. The other options do not belong as key design elements of an IT risk management programme: an incident response plan (B) and a business continuity plan (C) are operational response and recovery capabilities that may be informed by risk assessments but are not themselves risk programme design components, and a vendor management policy (D) is a third-party governance control that addresses only one risk domain rather than the overall programme structure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk assessment methodology

    Why this is correct

    A defined risk assessment methodology is essential because it establishes consistent likelihood and impact criteria, enabling risks to be identified, analysed and prioritised against the organisation's risk appetite. This directly satisfies the stem's requirement for governance integration, since IT governance depends on repeatable, comparable risk evaluations feeding escalation and oversight processes.

  • ✗

    Incident response plan

    Why it's wrong here

    An incident response plan is an operational control executed after an event, not a design element of the risk programme itself. It is tempting because incident handling supports risk treatment, but programme design covers governance, appetite, assessment methodology and reporting.

  • ✗

    Business continuity plan

    Why it's wrong here

    A business continuity plan is a recovery capability invoked after disruption, not a component of risk programme design. It is tempting because continuity depends on risk assessment outputs, but design elements are governance structure, risk appetite, assessment approach and monitoring.

  • ✗

    Vendor management policy

    Why it's wrong here

    A vendor management policy governs third-party relationships, not the design of an IT risk management programme itself, which centres on risk appetite, identification, assessment and treatment processes. It is tempting because vendor risk is a genuine component, and such a policy would be the right artefact when scoping third-party risk specifically.

  • ✓

    Risk register

    Why this is correct

    A risk register provides the centralised record of identified IT risks, their owners, likelihood, impact and treatment status, satisfying the stem's requirement for a structured programme element. It operationalises risk identification and monitoring, enabling governance bodies to track exposure against appetite and evidence that risk management is integrated with IT governance decisions.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.