Certified in Risk and Information Systems Control (CRISC) — Question 727
When reporting risk assessment results to senior management, which of the following is MOST important to include to enable risk-based decision making?
Answer options
- A. A list of assets exposed to the highest risk
- B. Potential losses compared to treatment cost
- C. Recent audit and self-assessment results
- D. Risk action plans and associated owners
Correct answer: B
Explanation
The correct answer, B, is crucial as it directly compares potential financial losses with the costs of treatment, enabling informed risk-based decisions. Options A, C, and D provide relevant information but do not directly facilitate the decision-making process as effectively as understanding the cost-benefit analysis of potential losses versus treatment expenses.