CRISC Risk Response and Reporting Practice Question
An organization is planning to implement a new security control. The project manager must ensure changes to existing systems are properly managed. Which process is most critical to include in the implementation plan?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management
Change management ensures that changes to systems are controlled, tested, and approved to prevent unintended disruptions or security gaps. It is essential during control implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User training
Why it's wrong here
User training addresses human behaviour and awareness; it does not authorise, test or document modifications to existing systems during deployment. It is tempting because new controls often require users to adopt new practise, and it would be the right choice where the risk is staff misuse rather than uncontrolled change.
- ✓
Change management
Why this is correct
Change management governs how modifications to existing systems are assessed, approved and recorded, directly satisfying the project manager's need to control alterations during implementation. It prevents unauthorised or untested changes disrupting production, aligning the security control rollout with established baselines and audit trails required under CRISC's change control domain.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning identifies weaknesses in systems; it does not govern or approve modifications made while implementing the control. It is tempting because it is a recurring security activity around systems, and it would be correct where the objective is detecting known flaws rather than managing change.
- ✗
Access review
Why it's wrong here
Access review recertifies existing user entitlements on a periodic cycle; it does not control alterations to systems when a new control is deployed. It is tempting because it is a governance process touching systems, and it would be correct where standing privileges need periodic validation rather than change control.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.