Which of the following is MOST helpful when prioritizing action plans for identified risk?
A.
Comparing risk rating against appetite
B.
Obtaining input from business units
C.
Determining cost of controls to mitigate risk
D.
Ranking the risk based on likelihood of occurrence
The Answer Is:
A
This question includes an explanation.
Explanation:
Comparing risk rating against appetite is the most helpful criterion when prioritizing action plans for identified risk, as it helps to determine the urgency and importance of addressing the risk. Risk rating is the level of risk after considering the likelihood and impact of a risk event, and risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives. By comparing risk rating against appetite, an organization can identify which risks are above, within, or below its tolerance level, and prioritize the action plans accordingly. Risks that are above the appetite level should be treated with the highest priority, as they pose asignificant threat to the organization’s objectives and performance. Risks that are within the appetite level should be monitored and controlled regularly, as they are acceptable but still require attention. Risks that are below the appetite level should be reviewed periodically, as they are negligible or insignificant.
[References:, •ISACA, Risk IT Framework, 2nd Edition, 2019, p. 751, •ISACA, Tips for Prioritizing Risk in Your Risk Register2, , , , , , , , , ]
CRISC PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"