Certified in Risk and Information Systems Control (CRISC) — Question 704
Which of the following is MOST effective in continuous risk management process improvement?
Answer options
- A. Policy updates
- B. Periodic assessments
- C. Awareness training
- D. Change management
Correct answer: B
Explanation
Periodic assessments are crucial as they allow organizations to regularly evaluate their risk management processes and identify areas for improvement. While policy updates, awareness training, and change management are important, they are less focused on the continuous evaluation aspect that is key to effective risk management.