Certified in Risk and Information Systems Control (CRISC) — Question 612
Which of the following provides the MOST comprehensive information when developing a risk profile for a system?
Answer options
- A. Risk assessment results
- B. Key performance indicators (KPIs)
- C. A mapping of resources to business processes
- D. Results of a business impact analysis (BIA)
Correct answer: A
Explanation
The correct answer, A, is right because risk assessment results provide a thorough evaluation of potential threats and vulnerabilities associated with a system. The other options, while useful, do not offer the same level of depth in addressing risks; KPIs measure performance, resource mapping relates to operational efficiency, and BIA results focus on impact rather than risk specifics.