Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?

⚠ Common exam trap

Many exam-takers think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using consistent risk metrics and terminology across IT and enterprise levels

Option A is correct because using consistent risk metrics and terminology across IT and enterprise levels enables IT risk data to be aggregated, compared, and communicated within the ERM framework rather than being siloed in IT-specific language. Option B is correct because aligning IT risk appetite with enterprise risk appetite ensures IT risk tolerances and thresholds are derived from and consistent with the organization's overall risk appetite, which is a core requirement of ERM integration. Option C is correct because reporting IT risk as a component of broader operational risk allows IT risk to be consolidated into enterprise risk reporting, giving leadership a holistic view of risk exposure. Option D does not belong because maintaining a separate IT risk register not shared with ERM perpetuates silos and prevents aggregation and enterprise-level visibility. Option E does not belong because reporting IT risks only to the CIO without board visibility excludes key governance stakeholders and contradicts the top-down, board-engaged nature of ERM integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using consistent risk metrics and terminology across IT and enterprise levels

    Why this is correct

    Shared metrics and terminology let IT risk data roll up into enterprise reporting without translation loss, enabling aggregation and comparison across the ERM framework. This consistency is a foundational integration activity, aligning how risk is measured and described at both levels.

  • ✓

    Aligning IT risk appetite with enterprise risk appetite

    Why this is correct

    Aligning IT risk appetite with enterprise risk appetite ensures technology risk tolerance stays within the boundaries set by the board, so IT decisions reflect organisational risk limits. This cascading alignment is a core integration activity linking IT risk governance to ERM.

  • ✓

    Reporting IT risk as a component of broader operational risk

    Why this is correct

    Reporting IT risk as a component of operational risk places technology exposures within the enterprise taxonomy, enabling the ERM function to aggregate and compare them alongside other operational risks. This consistent classification supports integrated enterprise-wide risk reporting.

  • ✗

    Maintaining a separate IT risk register not shared with ERM

    Why it's wrong here

    A separate IT risk register isolates IT risk data from enterprise risk aggregation, preventing the consolidated view integration requires. It is tempting because dedicated registers do give IT teams granular tracking of technical risks, making them the right choice when IT risks are too detailed or numerous for the enterprise register.

  • ✗

    Reporting IT risks only to the CIO without board visibility

    Why it's wrong here

    Restricting reporting to the CIO denies the board and ERM function the visibility needed to aggregate and govern IT risk enterprise-wide. It is tempting because CIO-only reporting does suit purely operational escalations, making it the right choice when a technical issue requires rapid executive action rather than board oversight.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.