A risk practitioner is updating the risk register after a third-party security incident. Which of the following is the MOST important information to include in the risk register entry for this third-party risk?
Recording the risk event, its impact and the response taken captures what occurred, the consequence and the mitigation, enabling accurate risk register updates and future comparison. This satisfies the stem's need for the most important entry content after a third-party incident.
Why this answer
A risk register entry must capture the essential elements of the risk: a description of the risk event, its potential or realized impact, and the response taken (or planned). For a third-party security incident, documenting what happened, how it affects the organization, and what was done provides the basis for risk tracking, reporting, and future decision-making. This is the core content that makes the register actionable.
Exam trap
CRISC often tests the distinction between incident details (dates, data volumes, contacts) and the structured risk information (description, impact, response) that belongs in a risk register — candidates may pick incident specifics over the risk-centric content.
How to eliminate wrong answers
Option A is wrong because a remediation plan and signature are important governance artifacts but secondary to the fundamental risk description, impact, and response — without those, the plan lacks context. Option B is wrong because incident date and data volume are incident-specific details, not the structured risk information needed for ongoing risk management and prioritization. Option D is wrong because third-party contact details are vendor management data, not risk register content — they belong in a vendor inventory or contract repository.