CRISC Risk Response and Reporting Practice Question
An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?
⚠ Common exam trap
Many exam-takers think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using consistent risk metrics and terminology across IT and enterprise levels
Using consistent risk metrics and terminology across IT and enterprise levels ensures that IT risks are communicated in a language that the broader ERM framework understands, enabling aggregation and comparison. This alignment prevents siloed risk assessments and supports a unified view of risk exposure across the organization, which is a foundational requirement for integrating IT risk into ERM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using consistent risk metrics and terminology across IT and enterprise levels
Why this is correct
Consistency enables aggregation and comparison.
- ✓
Aligning IT risk appetite with enterprise risk appetite
Why this is correct
Alignment ensures IT risk decisions are within enterprise boundaries.
- ✓
Reporting IT risk as a component of broader operational risk
Why this is correct
This aligns IT risk with ERM categories.
- ✗
Maintaining a separate IT risk register not shared with ERM
Why it's wrong here
Separate registers prevent integration.
- ✗
Reporting IT risks only to the CIO without board visibility
Why it's wrong here
This limits integration; board visibility is needed.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.