CRISC - Information Technology and Security - Section 4.5

Address IT risk across the system development life cycle and the adoption of emerging technologies.

Address IT risk at each phase of the system development life cycle - from requirements through design, development, testing, and deployment - by embedding secure development practices from the outset. Apply the same risk lens to the adoption of emerging technologies, where immature practices and limited vendor track records introduce additional uncertainty.

System development life cycleSecure developmentEmerging technologiesTechnology adoption

Practice question for this objective

Free sampleInformation Technology and Securitymedium

An enterprise is piloting Internet of Things sensors across its factory floor and plans a wider rollout. The risk practitioner is asked how to keep the related IT risk visible to decision makers as adoption grows. Which action BEST supports ongoing risk oversight?

  • ARecord the pilot risks once in the project file and close them when the pilot ends, since the wider rollout is a separate later initiative.
  • BDelegate all sensor risk decisions to the vendor under the support contract, as the vendor understands the devices better than internal staff.
  • CAdd the emerging technology exposures to the enterprise risk register and report them to governance as the deployment scales and changes. Correct
  • DWait until a sensor security incident occurs and then brief governance, because that is the point at which the exposure becomes a confirmed reality.
Emerging technology exposures should be tracked in the risk register and reported to governance as deployment scales, keeping oversight continuous rather than one-off. Adding the sensor exposures to the enterprise risk register and reporting them as the deployment grows creates a continuous, visible link between the changing technology footprint and the people accountable for risk decisions, so oversight keeps pace with the rollout instead of lapsing after a pilot or waiting for an incident to force attention.

Why A is wrong: Closing the risks at pilot end feels tidy, but the exposures persist and scale with the rollout, so a one-off record leaves later decisions uninformed.

Why B is wrong: Vendor expertise is useful, yet delegating the decisions transfers neither accountability nor the enterprise's obligation to manage risk within its own appetite.

Why C is correct: Recording the exposures in the risk register and reporting them as the deployment grows keeps decision makers informed and supports ongoing, risk-based oversight.

Why D is wrong: Briefing only after an incident is purely reactive and denies decision makers the chance to act on the exposure before it is exploited.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Information Technology and Security objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.