Courseiva
Risk Response and ReportingmediumMultiple ChoiceObjective-mapped

CRISC Risk Response and Reporting Practice Question

Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?

⚠ Common exam trap

ISACA often tests the misconception that ERM integration aims to replace or reduce IT-specific risk management activities, when in fact it seeks to elevate IT risk visibility to the enterprise level without eliminating specialized IT risk processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To provide a holistic view of risk across the organization

Integrating IT risk reporting into the ERM program provides a holistic view of risk across the organization by aligning IT-specific risks with strategic, operational, and compliance risks. This integration ensures that decision-makers can prioritize and respond to risks based on their aggregate impact, rather than treating IT risks in isolation. The primary purpose is to enable a unified risk posture that supports enterprise-wide governance and resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To reduce the frequency of IT risk reporting

    Why it's wrong here

    Frequency may change but is not the primary purpose.

  • To eliminate the need for IT risk assessments

    Why it's wrong here

    Integration does not eliminate assessments.

  • To provide a holistic view of risk across the organization

    Why this is correct

    ERM integration ensures IT risk is seen in context of overall risk.

  • To replace IT risk management with ERM

    Why it's wrong here

    Integration does not replace IT risk management; it aligns them.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.