Risk Response and Control Ownership
This chapter marks the beginning of Domain 3: Risk Response and Reporting for CRISC. This domain represents 32 percent (approximately 48 questions) of the revised CRISC exam. As a reminder, Domain 2 of the CRISC exam and the material we learned until Chapter 9, Business Impact Analysis, and Inherent and Residual Risk, focused on IT risk assessment, which relates to IT risk analysis and assessment. This and the following three chapters focus on risk response, control design and implementation, and risk monitoring and reporting.
The aim of this chapter is to introduce the concepts of risk response and monitoring and risk and control ownership, take a deeper dive into the risk response strategies – mitigate/accept/transfer/avoid – and ultimately learn about risk optimization.
In this chapter, we will cover the following topics:
- Risk response and monitoring
- Risk owners and control owners
- Risk response strategies ...