Certified in Risk and Information Systems Control (CRISC) — Question 608
Which of the following resources is MOST helpful to a risk practitioner when updating the likelihood rating in the risk register?
Answer options
- A. Business impact analysis (BIA)
- B. Risk control assessment
- C. Penetration test results
- D. Audit reports with risk ratings
Correct answer: B
Explanation
The correct answer is B, as a Risk Control Assessment provides insights into the effectiveness of existing controls and their impact on risk likelihood. Options A, C, and D, while valuable, do not focus specifically on assessing the likelihood of risks, making them less relevant for this task.