Courseiva

CRISC Information Technology and Security Practice Question

An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?

⚠ Common exam trap

CRISC often tests the distinction between governance elements (policy) and operational elements (methodology, process, register); candidates may incorrectly choose the policy because it sounds foundational, but the question asks for the component ensuring consistent identification and assessment, which is the methodology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk assessment methodology

A risk assessment methodology provides a standardized approach for identifying, analyzing, and evaluating risks. It ensures that all business units use consistent criteria, scales, and processes, which is essential for comparing and aggregating risks across the enterprise. Without a common methodology, risk assessments become subjective and inconsistent, undermining the risk management program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk assessment methodology

    Why this is correct

    A defined risk assessment methodology supplies common criteria, scales and scoring, so different business units identify and evaluate risks consistently. Without it, assessments vary by assessor and cannot be aggregated, failing the stem's requirement for enterprise-wide consistency in identification and assessment.

  • ✗

    Risk treatment process

    Why it's wrong here

    Risk treatment addresses responses to assessed risks, not the consistent identification and assessment that precedes treatment. It is tempting because treatment is a core programme phase, and it would be the correct answer if the question asked how the organisation selects and implements controls to modify identified risks.

  • ✗

    Risk management policy

    Why it's wrong here

    A policy states intent but does not itself enforce consistent identification and assessment; the risk register is the instrument that records and tracks risks uniformly. A policy is tempting because governance documents underpin programmes, yet it would be the answer when the question asks what establishes authority and mandate rather than the mechanism ensuring consistency.

  • ✗

    Risk register

    Why it's wrong here

    The risk register records identified risks and assessments but does not by itself ensure consistent identification across the enterprise; that requires a defined methodology or framework. It is tempting because it is the central artefact of risk management, and it would be correct if the question asked where risks and their assessments are documented and tracked.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.