Certified Information Systems Security Professional (CISSP) — Question 133

During the change management process, which of the following is used to identify and record new risks?

Answer options

Correct answer: C

Explanation

The Risk register is the appropriate tool for identifying and recording new risks as it is specifically designed for tracking all identified risks throughout a project. The Risk assessment is focused on evaluating existing risks, the Lessons learned register captures insights from past projects, and the Risk report summarizes risk status but does not specifically record new risks.