CRISC · Domain 3
Risk Response and Reporting
About 32% of the exam
Response options
- Choose by cost against risk reduction
- Respect appetite, tolerance and law
- Accountability never transfers with the risk
- Acceptance above appetite needs senior approval
- Avoid
- exit the activity, remove the exposure
- Mitigate
- add or strengthen controls
- Transfer or share
- insurance, contracts, outsourcing
- Accept
- owner signs, within appetite, documented
- Exploit
- positive risk, pursue the opportunity
- Not an option
- ignore or defer indefinitely
Response is a business decision made by the risk owner with the practitioner's analysis in hand
Choosing a response
- Cost of control below value at risk
- Consider likelihood and impact separately
- Check dependencies on other controls
- Time to implement versus exposure window
- Regulatory minimums are not negotiable
- Prefer the option that fixes the cause
- Document the rationale, not only the choice
Risk and control ownership
- Risk owner
- business manager, decides the response
- Control owner
- implements, operates, monitors
- Action owner
- delivers the treatment plan
- Practitioner
- advises, tracks, reports
- Senior management
- approves exceptions to appetite
If nobody owns it, nobody responds; the register must show a name, not a department
Control types and functions
- Preventive
- stop the event happening
- Detective
- find it during or after
- Corrective
- fix and restore
- Deterrent
- discourage the attempt
- Compensating
- alternative meeting the same objective
- Managerial, technical, physical
- the three categories
Design versus operating effectiveness
- Design
- would it work if performed
- Operating
- did it work over the period
- Test methods
- inquiry, observation, inspection, reperformance
- Self-assessment
- owners rate their own controls
- Independent test
- audit or second line validates
- Deficiency
- raise risk, plan remediation
Design is assessed once per change; operation is assessed repeatedly over time
Control monitoring
- First: define which controls and criteria
- Frequency follows risk and criticality
- Continuous where automation allows
- Monitoring is ongoing, audit is periodic
- Baselines make change visible
- Compensating controls watched more closely
- Results feed the next risk reassessment
Exceptions and issues
- Exception report: control did not operate
- Rising exception trend means degradation
- Root cause before remediation
- Track every exception to closure
- Unauthorized override: document, assess, enforce
- Consistent failure: remediate, replace, compensate
- Incident in the area triggers immediate review
KRI, KPI and KCI
KRI, key risk indicator
- Early warning exposure is rising
- Leading, predictive, threshold based
- Tied to a register entry
- Example: privileged accounts without review
KPI, key performance indicator
- How well a process performs
- Often lagging, measures results
- Example: patch SLA compliance percent
- Owned by the process manager
KCI, key control indicator
- Is the control operating as designed
- Example: percent of logs reviewed
- Feeds control effectiveness conclusions
- Owned by the control owner
KRI warns about the risk, KCI reports on the control, KPI reports on the process
Good indicator traits
- Measurable, repeatable, consistently defined
- Timely enough to allow action
- Threshold linked to appetite and tolerance
- Sensitive: moves when the risk moves
- Few and meaningful over many and noisy
- Owner and escalation route named
- Reviewed when the risk changes
Register upkeep
- Update after every assessment and response
- Close risks only with owner sign-off
- Link controls, KRIs and action plans
- Record acceptance with date and approver
- Aggregate duplicates into one entry
- Review dates drive the reassessment cycle
- Audit trail of every rating change
Reporting to the board
What to show
- Residual risk against appetite
- Top risks, trend and direction
- KRI breaches and what was done
- Open actions, overdue items, exceptions
- Emerging risks needing a decision
How to show it
- Business impact, not technical detail
- Consistent scales across the enterprise
- Heat map plus a short narrative
- Frequency matched to decision cadence
- Recommendations with options and costs
The board needs to decide, not to be impressed; every slide should end in a decision or an assurance
Action plans and tracking
- Each response becomes a plan with owner
- Milestones, due dates, budget, dependencies
- Interim risk while the plan runs
- Verify the control works before closing
- Overdue plans escalate to management
- Residual rerated after implementation
- Lessons fed back into methodology
Rapid recall: the FIRST move
- Confirm the risk owner before proposing
- Compare control cost to risk reduced
- Residual above appetite: escalate for decision
- Exception found: root cause, then fix
- Overdue reviews: escalate and investigate cause
- Report in business terms to the board
- Verify effectiveness before declaring done
Reference strip: options, controls, indicators, reporting
Response options
- Avoid: stop the activity
- Mitigate: add controls
- Transfer or share: insurance, contract
- Accept: owner signs within appetite
- Exploit: positive risk pursued
Control vocabulary
- Preventive, detective, corrective, deterrent
- Compensating: same objective, different means
- Managerial, technical, physical
- Design versus operating effectiveness
- Inquiry, observation, inspection, reperformance
Indicators
- KRI: risk early warning
- KCI: control operating status
- KPI: process performance
- Leading predicts, lagging reports
- Threshold tied to tolerance
Monitoring words
- Continuous monitoring versus periodic audit
- Control self-assessment by owners
- Exception report and trend
- Baseline and drift
- Root cause analysis
Board reporting
- Residual against appetite
- Top risks and trends
- KRI breaches and responses
- Overdue actions and exceptions
- Decisions requested of the board
Quick exam traps
- Trap: Transferring a risk through insurance removes the owner's accountability
- Trap: Accepting a risk means no further monitoring is needed
- Trap: A KRI and a KPI are two names for the same metric
- Trap: A control that passed design review is operating effectively
- Trap: Control monitoring and internal audit are the same activity
- Trap: The risk practitioner selects the response on behalf of the business
- Trap: Board reports should include full technical detail for completeness
- Trap: Meeting the patch SLA proves systems are patched
cybercertprep.com · original revision sheet written from the public body of knowledge