CRISC - Governance (26% of the exam) - Section 1.7

Apply enterprise risk management concepts and a risk management framework to govern IT risk.

Apply enterprise risk management concepts from frameworks such as COSO ERM and COBIT to govern IT risk as part of the broader organisational risk universe. Distinguish between the roles each framework plays and select the elements appropriate to the organisation's maturity and context.

Enterprise risk managementRisk management frameworkCOSO ERMCOBIT

Practice question for this objective

Free sampleGovernancehard

An enterprise has adopted COBIT to govern IT and wants its IT risk management to demonstrably support enterprise objectives rather than operate as a standalone technical exercise. Which approach best embeds IT risk within the enterprise risk management framework using COBIT?

  • AMaintaining the IT risk register inside the security team and reporting it only to the IT director each quarter
  • BCascading enterprise goals to IT-related goals and aligning risk responses to those mapped objectives Correct
  • CRanking IT risks purely by the technical severity scores produced by the vulnerability scanning platform
  • DOutsourcing IT risk assessment to an external firm that benchmarks the enterprise against industry peers
Using COBIT's goals cascade to link enterprise goals to IT goals lets risk responses be aligned to business objectives rather than treated as standalone technical work. COBIT provides a goals cascade that derives IT-related goals from enterprise goals; aligning risk identification and response to that chain ensures IT risk decisions are justified by their effect on business objectives, which is what embedding IT risk in the enterprise framework requires.

Why A is wrong: Keeping risk inside the security team is common practice, but siloed reporting to IT alone is exactly the standalone posture the enterprise is trying to move away from.

Why B is correct: COBIT's goals cascade traces enterprise goals to IT-related goals, so aligning risk responses to that mapping is what makes IT risk demonstrably support business objectives.

Why C is wrong: Technical severity is useful input, yet ranking on scanner scores alone ignores business impact and so fails to connect IT risk to the enterprise objectives it should serve.

Why D is wrong: External benchmarking can inform maturity, but delegating assessment outward does not build the internal goals-cascade linkage that embeds IT risk in enterprise objectives.

See more CRISC practice questions, answers explained.

Exam traps in Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • A certified list of mandatory technical controls that every business system is then obliged to implement without exception

    Why it is wrong: A control catalogue is attractive because it feels concrete, but COSO ERM is a governance framework that integrates risk with strategy, not a prescriptive list of technical controls to install.

  • Delegation of all IT risk acceptance decisions down to each individual business unit risk owner

    Why it is wrong: Pushing acceptance to unit owners feels efficient and empowering, but it deepens the inconsistency the board complained about rather than enabling comparison across units.

  • Re-running the full annual control test cycle earlier than scheduled so that every control is evidenced against its current design

    Why it is wrong: Earlier control testing assures existing controls, but it does not update categories, appetite or process to fit a changed enterprise, which is the gap the practitioner needs to close.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.