Certified in Risk and Information Systems Control (CRISC) — Question 1310
Which of the following would produce the MOST comprehensive and relevant enterprise risk scenarios?
Answer options
- A. Conduct risk assessment workshops with business process owners.
- B. Conduct risk assessment workshops with risk owners.
- C. Leverage current and historical data to inform risk scenarios.
- D. Combine top-down and bottom-up approaches.
Correct answer: D
Explanation
The correct answer, D, is effective because it incorporates insights from both upper management and operational levels, resulting in a well-rounded understanding of risks. The other options focus on either a single perspective or data analysis, which may not capture the full scope of potential risks.