Certified in Risk and Information Systems Control (CRISC) — Question 809
An organization has used generic risk scenarios to populate its risk register. Which of the following presents the GREATEST challenge to assigning ownership of the associated risk entries?
Answer options
- A. The volume of risk scenarios is too large.
- B. Risk scenarios are not applicable.
- C. The risk analysis for each scenario is incomplete.
- D. Risk aggregation has not been completed.
Correct answer: B
Explanation
The correct answer is B because if the risk scenarios do not apply, it becomes impossible to assign ownership effectively, as there would be no relevant risks to manage. Option A may present a challenge, but it does not directly impact ownership assignment like irrelevant scenarios do. Options C and D indicate issues with risk analysis and aggregation, but they do not inherently prevent ownership assignment as much as irrelevance does.