Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Full Access Isaca CRISC Tutorials

Page: 13 / 136
Total 1810 questions

Certified in Risk and Information Systems Control Questions and Answers

Question 49

Key risk indicators (KRIs) BEST support risk treatment when they:

Options:

A.

Set performance expectations for controls.

B.

Align with key business objectives.

C.

Indicate that the risk is approaching predefined thresholds.

D.

Articulate likelihood and impact in quantitative terms.

Question 50

Which of the following is MOST essential for an effective change control environment?

Options:

A.

Business management approval of change requests

B.

Separation of development and production environments

C.

Requirement of an implementation rollback plan

D.

IT management review of implemented changes

Question 51

External auditors have found that management has not effectively monitored key security technologies that support regulatory objectives. Which type of indicator would BEST enable the organization to identify and correct this situation?

Options:

A.

Key Performance Indicator (KPI)

B.

Key Management Indicator (KMI)

C.

Key Risk Indicator (KRI)

D.

Key Control Indicator (KCI)

Question 52

An organization's IT infrastructure is running end-of-life software that is not allowed without exception approval. Which of the following would provide the MOST helpful information to justify investing in updated software?

Options:

A.

The balanced scorecard

B.

A cost-benefit analysis

C.

The risk management frameworkD, A roadmap of IT strategic planning

Page: 13 / 136
Total 1810 questions