CRISC Risk Response and Reporting Practice Question
Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?
⚠ Common exam trap
ISACA often tests the misconception that ERM integration aims to replace or reduce IT-specific risk management activities, when in fact it seeks to elevate IT risk visibility to the enterprise level without eliminating specialized IT risk processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide a holistic view of risk across the organization
Integrating IT risk reporting into the ERM program provides a holistic view of risk across the organization by aligning IT-specific risks with strategic, operational, and compliance risks. This integration ensures that decision-makers can prioritize and respond to risks based on their aggregate impact, rather than treating IT risks in isolation. The primary purpose is to enable a unified risk posture that supports enterprise-wide governance and resource allocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To reduce the frequency of IT risk reporting
Why it's wrong here
Frequency may change but is not the primary purpose.
- ✗
To eliminate the need for IT risk assessments
Why it's wrong here
Integration does not eliminate assessments.
- ✓
To provide a holistic view of risk across the organization
Why this is correct
ERM integration ensures IT risk is seen in context of overall risk.
- ✗
To replace IT risk management with ERM
Why it's wrong here
Integration does not replace IT risk management; it aligns them.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.