Courseiva

CRISC Risk Response and Reporting Practice Question

An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change management

Change management ensures that changes to systems are controlled, tested, and approved to prevent unintended disruptions or security gaps. It is essential during control implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User training

    Why it's wrong here

    User training addresses human behaviour and awareness; it does not authorise, test or document modifications to existing systems during deployment. It is tempting because new controls often require users to adopt new practise, and it would be the right choice where the risk is staff misuse rather than uncontrolled change.

  • ✓

    Change management

    Why this is correct

    Change management governs how modifications to existing systems are assessed, approved and recorded, directly satisfying the project manager's need to control alterations during implementation. It prevents unauthorised or untested changes disrupting production, aligning the security control rollout with established baselines and audit trails required under CRISC's change control domain.

  • ✗

    Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning identifies weaknesses in systems; it does not govern or approve modifications made while implementing the control. It is tempting because it is a recurring security activity around systems, and it would be correct where the objective is detecting known flaws rather than managing change.

  • ✗

    Access review

    Why it's wrong here

    Access review recertifies existing user entitlements on a periodic cycle; it does not control alterations to systems when a new control is deployed. It is tempting because it is a governance process touching systems, and it would be correct where standing privileges need periodic validation rather than change control.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.