CRISC - Information Technology and Security - Section 4.3

Identify and manage IT risk arising in projects and programme delivery.

Identify IT-specific risk categories within projects and programme delivery, including delivery risk, scope creep, and technology integration failure. Apply programme governance practices to ensure risk identification and treatment are embedded throughout the project lifecycle rather than treated as a post-delivery exercise.

Project managementProject riskDelivery riskProgramme governance

Practice question for this objective

Free sampleInformation Technology and Securityeasy

An enterprise runs several related IT projects together as a single programme. What is the MAIN benefit of governing these projects at the programme level rather than entirely on their own?

  • AIt removes the need for each individual project to maintain its own separate risk register entirely.
  • BIt guarantees that every project within the programme will be delivered on time and within its budget.
  • CIt allows shared risks and dependencies across the projects to be coordinated and managed together. Correct
  • DIt transfers accountability for project risks from the project managers up to the programme sponsor.
Programme governance coordinates risks and dependencies that span related projects, giving an enterprise view that individual project management cannot. Managing related projects as a programme creates a single layer of governance that sees dependencies and shared risks crossing project boundaries, allowing conflicts, resource contention and aggregated exposure to be managed coherently rather than slipping through the gaps between independently run projects.

Why A is wrong: Programmes coordinate risk but do not abolish project-level registers; each project still tracks its own risks that then roll up to the programme.

Why B is wrong: Governance improves oversight, but no structure can guarantee on-time, on-budget delivery, so this overstates what programme management can deliver.

Why C is correct: Programme governance gives one view of cross-project risks and dependencies, so conflicts and shared exposures are coordinated rather than missed between separate teams.

Why D is wrong: Sponsors gain oversight, yet project managers retain accountability for their own risks; programme governance coordinates rather than reassigns that ownership.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Information Technology and Security objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.