Certified in Risk and Information Systems Control (CRISC) — Question 443
Who should be responsible for determining which stakeholders need to be involved in the development of a risk scenario?
Answer options
- A. Risk owner
- B. Control owner
- C. Compliance manager
- D. Risk practitioner
Correct answer: D
Explanation
The Risk practitioner is the individual best suited to identify which stakeholders are necessary for the development of a risk scenario, as they possess the knowledge and expertise to assess risks effectively. The other roles, such as Risk owner and Control owner, may have specific responsibilities but do not typically focus on stakeholder engagement in risk scenario development.