Certified in Risk and Information Systems Control (CRISC) — Question 649
Which of the following is the BEST reason to use qualitative measures to express residual risk levels related to emerging threats?
Answer options
- A. Qualitative measures are easier to update.
- B. Qualitative measures are better aligned to regulatory requirements.
- C. Qualitative measures are better able to incorporate expert judgment.
- D. Qualitative measures require less ongoing monitoring.
Correct answer: C
Explanation
The correct answer is C because qualitative measures allow for the inclusion of subjective expert opinions, which can provide deeper insights into emerging threats. In contrast, options A, B, and D do not capture the unique strength of qualitative measures in leveraging expert judgment, which is crucial for assessing new and complex risk scenarios.