Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner at a healthcare insurer is mapping the organization's IT risk register to the NIST Cybersecurity Framework (CSF) 2.0. Executive leadership wants assurance that the organization understands which assets and business processes depend on which systems before any risk treatment decisions are made. Which CSF 2.0 function and category BEST addresses this requirement?

⚠ Common exam trap

The trap here is assuming that any governance or risk strategy category satisfies an executive request for asset visibility, when dependency mapping is really an IDENTIFY function activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IDENTIFY (ID) — Asset Management (ID.AM)

The insurer needs to know which systems support which business processes before deciding on treatment, and that dependency mapping is the core purpose of the IDENTIFY function's Asset Management category. Governance sets direction, PROTECT enforces controls, and DETECT finds events, but none of those produces the asset-to-process inventory that leadership explicitly requested.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IDENTIFY (ID) — Asset Management (ID.AM)

    Why this is correct

    ID.AM requires the organization to inventory hardware, software, services, and systems and to map them to business functions and processes. For the healthcare insurer, this directly produces the asset-to-business-process dependency view leadership is asking for, making it the correct foundation before any risk response or treatment decision is taken.

  • ✗

    DETECT (DE) — Continuous Monitoring (DE.CM)

    Why it's wrong here

    DE.CM covers monitoring networks, personnel activity, and external service providers to find anomalies and adverse events. Detection is downstream of knowing what assets and dependencies matter; without an asset and dependency baseline the insurer would generate alerts with no business context, so this category does not satisfy the stated requirement.

  • ✗

    GOVERN (GV) — Risk Management Strategy (GV.RM)

    Why it's wrong here

    GV.RM establishes risk appetite, tolerance, and strategic direction for managing cyber risk, but it does not itself inventory assets or map business process dependencies. The insurer's requirement to understand what depends on what is an asset and dependency identification activity, which sits in the IDENTIFY function, not in the governance-oriented risk strategy category.

  • ✗

    PROTECT (PR) — Identity Management, Authentication, and Access Control (PR.AA)

    Why it's wrong here

    PR.AA focuses on controlling logical and physical access to assets through identity proofing, credential management, and least privilege. While important, it assumes the organization already knows which assets exist and what they support; it does not deliver the dependency mapping the insurer needs to prioritize risk treatment across business processes.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.