Certified in Risk and Information Systems Control (CRISC) — Question 1449

Which of the following BEST indicates the condition of a risk management program?

Answer options

Correct answer: B

Explanation

The amount of residual risk is the best indicator as it reflects the risk remaining after controls are implemented. The number of controls and risk register entries do not provide a complete picture of how well risks are being managed, while the level of financial support does not directly correlate to the effectiveness of the risk management program.