Certified in Risk and Information Systems Control (CRISC) — Question 581
Whether the results of risk analysis should be presented in quantitative or qualitative terms should be based PRIMARILY on the:
Answer options
- A. specific risk analysis framework being used.
- B. results of the risk assessment.
- C. requirements of management.
- D. organizational risk tolerance.
Correct answer: C
Explanation
The correct answer is C, as the requirements of management significantly influence how risk analysis results are communicated. Options A and B are relevant but secondary to management's needs, while D refers to the overall organizational stance on risk rather than the specific presentation format.