Correct answer & explanation
✓Governance: Focuses on establishing and maintaining a framework for IT governance, including organizational structure, policies, and processes.
The four CRISC domains are Governance, IT Risk Assessment, Risk Response and Reporting, and Information Technology and Security. Each domain has a distinct focus: Governance sets the framework, IT Risk Assessment identifies and evaluates risks, Risk Response and Reporting handles responses and communication, and Information Technology and Security protects assets through controls and architecture. Common confusions include swapping Governance with IT Risk Assessment, as both involve risk management but at different levels.
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
How Courseiva writes practice questions · Editorial policy