Certified in Risk and Information Systems Control (CRISC) — Question 606
Which of the following is the BEST way to evaluate the risk awareness of control owners?
Answer options
- A. Conduct surveys and trend the results over time.
- B. Mandate risk awareness training for control owners.
- C. Include control owners in top-down risk workshops.
- D. Include control owners in risk committee meetings and risk reporting.
Correct answer: A
Explanation
Conducting surveys allows for quantitative measurement of control owners' risk awareness over time, making it the best option. While mandatory training (B) can improve awareness, it does not evaluate current understanding. Options C and D involve participation in discussions but do not directly assess individual risk awareness.