Courseiva

CRISC Information Technology and Security Practice Question

Which of the following is a key component of an IT risk management programme that documents identified risks, their likelihood, and impact?

⚠ Common exam trap

Many exam-takers confuse the risk register with the risk management policy, mistakenly thinking the policy document contains the detailed risk inventory, when in fact the policy only sets the governance framework while the register holds the operational risk data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk register

The risk register is the central repository within an IT risk management programme that formally documents identified risks, their assessed likelihood, and potential impact. It serves as the authoritative record for tracking risk ownership, mitigation status, and residual risk levels, enabling ongoing monitoring and reporting. Without a risk register, an organization cannot systematically manage or communicate its risk posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk management policy

    Why it's wrong here

    A risk management policy states the organisation's intent, scope and responsibilities for managing risk; it does not itself list individual risks with likelihood and impact values. It is tempting because policies govern the programme, but the risk register is the component that documents and scores each identified risk.

  • ✓

    Risk register

    Why this is correct

    A risk register is the central artefact that records each identified risk alongside its assessed likelihood and impact, giving the programme a single documented view for prioritisation and tracking. It directly satisfies the stem's requirement to document risks, likelihood and impact.

  • ✗

    Business continuity plan

    Why it's wrong here

    A business continuity plan sets out how critical operations continue during disruption; it does not enumerate risks with likelihood and impact assessments. It is tempting because continuity planning follows risk analysis, but the risk register is the component that documents identified risks and their ratings.

  • ✗

    Incident response plan

    Why it's wrong here

    An incident response plan documents procedures for detecting, containing and recovering from security incidents; it does not catalogue risks with likelihood and impact ratings. It is tempting because incident handling is part of risk treatment, but the risk register is the artefact that records and scores identified risks.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.