Certified in Risk and Information Systems Control (CRISC) — Question 630
A recent risk workshop has identified risk owners and responses for newly identified risk scenarios. Which of the following should be the risk practitioner's NEXT step?
Answer options
- A. Identify resources for implementing responses.
- B. Prepare a business case for the response options.
- C. Update the risk register with the results.
- D. Develop a mechanism for monitoring residual risk.
Correct answer: C
Explanation
The correct answer is C because updating the risk register is essential to document the identified risks and their responses, ensuring that all stakeholders are informed. Options A, B, and D are important steps but should follow the immediate need to update the risk register with the latest information.