CRISC Information Technology and Security Practice Question
A risk practitioner is evaluating the effectiveness of the organization's IT change management process. Which of the following metrics would BEST indicate that the process is effectively reducing risk?
⚠ Common exam trap
The trap here is focusing on efficiency metrics like speed or volume, which do not necessarily correlate with reduced risk, instead of a control adherence metric like testing coverage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of changes that are tested in a non-production environment before deployment.
The percentage of changes tested in a non-production environment is a leading indicator of effective change management. It shows that the organization is proactively identifying and mitigating risks before changes reach production. This directly reduces the likelihood of incidents caused by changes, making it the best metric for assessing risk reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of changes implemented per month.
Why it's wrong here
The volume of changes is not a measure of risk reduction. A high number of changes could increase risk if not properly managed, while a low number might indicate stagnation. This metric does not provide insight into the quality or safety of the change process, and therefore is not a good indicator of effective risk management.
- ✗
Percentage of changes that are rolled back due to failures.
Why it's wrong here
A high percentage of rollbacks indicates a problematic change management process, as it suggests changes are frequently causing issues. A low percentage might seem good, but it could also mean changes are not being tested or that failures are not being recorded. Rollback rate alone is not a direct indicator of risk reduction; it is a lagging indicator of process quality.
- ✓
Percentage of changes that are tested in a non-production environment before deployment.
Why this is correct
Testing changes in a non-production environment before deployment is a key preventive control in change management. A high percentage of changes tested indicates that the process is effectively identifying and mitigating potential issues before they affect production. This directly reduces the risk of service disruptions, data corruption, and security vulnerabilities introduced by changes.
- ✗
Average time to implement a change.
Why it's wrong here
While efficiency is desirable, speed alone does not indicate that risk is being reduced. In fact, rushing changes can increase risk if proper testing and approvals are bypassed. The average time to implement a change is a process efficiency metric, not a risk reduction metric. It should be balanced with quality and control metrics.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.