CRISC - Information Technology and Security (20% of the exam) - Section 4.3

Identify and manage IT risk arising in projects and programme delivery.

Identify IT-specific risk categories within projects and programme delivery, including delivery risk, scope creep, and technology integration failure. Apply programme governance practices to ensure risk identification and treatment are embedded throughout the project lifecycle rather than treated as a post-delivery exercise.

Project managementProject riskDelivery riskProgramme governance

Practice question for this objective

Free sampleInformation Technology and Securityeasy

An enterprise runs several related IT projects together as a single programme. What is the MAIN benefit of governing these projects at the programme level rather than entirely on their own?

  • AIt removes the need for each individual project to maintain its own separate risk register entirely.
  • BIt guarantees that every project within the programme will be delivered on time and within its budget.
  • CIt allows shared risks and dependencies across the projects to be coordinated and managed together. Correct
  • DIt transfers accountability for project risks from the project managers up to the programme sponsor.
Programme governance coordinates risks and dependencies that span related projects, giving an enterprise view that individual project management cannot. Managing related projects as a programme creates a single layer of governance that sees dependencies and shared risks crossing project boundaries, allowing conflicts, resource contention and aggregated exposure to be managed coherently rather than slipping through the gaps between independently run projects.

Why A is wrong: Programmes coordinate risk but do not abolish project-level registers; each project still tracks its own risks that then roll up to the programme.

Why B is wrong: Governance improves oversight, but no structure can guarantee on-time, on-budget delivery, so this overstates what programme management can deliver.

Why C is correct: Programme governance gives one view of cross-project risks and dependencies, so conflicts and shared exposures are coordinated rather than missed between separate teams.

Why D is wrong: Sponsors gain oversight, yet project managers retain accountability for their own risks; programme governance coordinates rather than reassigns that ownership.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Close the project risks alongside the project, because risks recorded for delivery no longer apply once the system has gone live.

    Why it is wrong: Closing the project does end delivery activity, but treating live operational risks as finished leaves the running system exposed with nobody managing those exposures.

  • The project manager, because they direct day-to-day delivery and are closest to the issues that arise during the work.

    Why it is wrong: The project manager runs delivery and manages tasks, but accountability for the business exposure rests with the sponsor who owns the outcome, not the delivery role.

  • Freeze the scope until the project is delivered, so the agreed baseline is protected and no further changes can disturb the plan.

    Why it is wrong: Protecting the baseline sounds disciplined, but refusing any change outright ignores legitimate needs and bypasses a risk-based evaluation of the request.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.