Certified in Risk and Information Systems Control (CRISC) — Question 971
A risk practitioner is developing a set of bottom-up IT risk scenarios. The MOST important time to involve business stakeholders is when:
Answer options
- A. identifying risk mitigation controls
- B. documenting the risk scenarios
- C. validating the risk scenarios
- D. updating the risk register
Correct answer: C
Explanation
Involving business stakeholders during the validation of risk scenarios is essential as they provide insights and perspectives that ensure the scenarios accurately reflect business realities. The other options, while important, do not require stakeholder input as critically as the validation phase, which confirms the relevance and accuracy of the identified risks.