Certified in Risk and Information Systems Control (CRISC) — Question 245
Which of the following would BEST help identify the owner for each risk scenario in a risk register?
Answer options
- A. Allocating responsibility for risk factors equally to asset owners.
- B. Determining resource dependency of assets.
- C. Mapping identified risk factors to specific business processes.
- D. Determining which departments contribute most to risk.
Correct answer: C
Explanation
Option C is correct as it directly associates risk factors with specific business processes, allowing for clear ownership of risks. The other options either distribute responsibility too broadly (A), focus on resource relationships without identifying owners (B), or do not directly tie risks to specific ownership (D).