Certified in Risk and Information Systems Control (CRISC) — Question 1395
You are the project manager of GHT project. You have planned the risk response process and now you are about to implement various controls. What you should do before relying on any of the controls?
Answer options
- A. Review performance data
- B. Discover risk exposure
- C. Conduct pilot testing
- D. Articulate risk
Correct answer: C
Explanation
Conducting pilot testing is essential to ensure that the controls work effectively in practice before full implementation. Reviewing performance data and discovering risk exposure are important, but they do not directly validate the effectiveness of the controls. Articulating risk is about communication, not testing controls.