Certified in Risk and Information Systems Control (CRISC) — Question 267
Which of the following should be the HIGHEST priority when developing a risk response?
Answer options
- A. The risk response is accounted for in the budget.
- B. The risk response aligns with the organization's risk appetite.
- C. The risk response is based on a cost-benefit analysis.
- D. The risk response addresses the risk with a holistic view.
Correct answer: B
Explanation
The highest priority in developing a risk response is ensuring that it aligns with the organization's risk appetite, as this ensures that the response is acceptable within the organization's overall risk management framework. While budget considerations, cost-benefit analysis, and a holistic view are important, they should not outweigh the need for alignment with the organization's risk tolerance.