Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is reviewing the organization's risk register and notices that a risk related to outdated encryption protocols on a file server has been assigned an owner. According to CRISC principles, what is the PRIMARY responsibility of the risk owner?

⚠ Common exam trap

The trap here is equating the risk owner with the person who implements controls, when actually the risk owner is accountable for decisions and oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure that the risk is managed appropriately and that decisions regarding its treatment are made and documented.

In CRISC, a risk owner is the individual accountable for managing a specific risk. Their primary responsibility is to ensure the risk is managed appropriately, which includes making and documenting decisions about risk treatment (accept, mitigate, transfer, avoid). They do not necessarily implement controls themselves, nor do they perform technical assessments or set organizational risk appetite. The risk owner ensures that the risk remains within tolerance and that actions are taken to address it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To implement the technical controls necessary to mitigate the risk to an acceptable level.

    Why it's wrong here

    Implementing technical controls is typically the responsibility of control owners, IT staff, or security engineers, not necessarily the risk owner. The risk owner is accountable for managing the risk, which may involve directing others to implement controls, but the hands-on implementation is usually delegated. This option confuses the accountability of the risk owner with the operational tasks of control execution. The risk owner ensures that appropriate actions are taken, not necessarily performs them.

  • ✓

    To ensure that the risk is managed appropriately and that decisions regarding its treatment are made and documented.

    Why this is correct

    The risk owner is accountable for the overall management of a specific risk, including making decisions about risk treatment, ensuring controls are in place, and monitoring the risk over time. In this scenario, the risk owner for the outdated encryption risk must decide whether to accept, mitigate, transfer, or avoid the risk and ensure that decision is documented. This aligns with CRISC's emphasis on clear ownership and accountability.

  • ✗

    To perform periodic vulnerability scans and penetration tests to identify changes in the risk profile.

    Why it's wrong here

    Performing vulnerability scans and penetration tests is a technical activity usually carried out by security operations or assessment teams. While the risk owner may request such tests, conducting them is not their primary responsibility. The risk owner focuses on risk treatment decisions and monitoring, not on executing technical assessments. This option misassigns operational security tasks to the risk owner role.

  • ✗

    To approve the organization's overall risk appetite statement and communicate it to the board of directors.

    Why it's wrong here

    Approving the overall risk appetite statement is typically the responsibility of senior management or the board, not an individual risk owner. The risk owner operates within the established risk appetite and manages specific risks. This option describes a governance-level responsibility that far exceeds the scope of a risk owner. Confusing the two roles would lead to an ineffective risk management structure.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.