Certified in Risk and Information Systems Control (CRISC) — Question 954

Who is MOST important to include in the assessment of existing IT risk scenarios?

Answer options

Correct answer: B

Explanation

Business process owners are vital in the assessment of IT risks as they have direct knowledge of the processes that could be impacted by these risks. While risk management consultants and technology experts provide valuable insights, they may not have the same level of understanding of the specific business operations as process owners do. Business users, though important, are not as directly involved in the overall risk management strategy as business process owners.