CRISC - Information Technology and Security (20% of the exam) - Section 4.5

Address IT risk across the system development life cycle and the adoption of emerging technologies.

Address IT risk at each phase of the system development life cycle - from requirements through design, development, testing, and deployment - by embedding secure development practices from the outset. Apply the same risk lens to the adoption of emerging technologies, where immature practices and limited vendor track records introduce additional uncertainty.

System development life cycleSecure developmentEmerging technologiesTechnology adoption

Practice question for this objective

Free sampleInformation Technology and Securitymedium

An enterprise is piloting Internet of Things sensors across its factory floor and plans a wider rollout. The risk practitioner is asked how to keep the related IT risk visible to decision makers as adoption grows. Which action BEST supports ongoing risk oversight?

  • ARecord the pilot risks once in the project file and close them when the pilot ends, since the wider rollout is a separate later initiative.
  • BDelegate all sensor risk decisions to the vendor under the support contract, as the vendor understands the devices better than internal staff.
  • CAdd the emerging technology exposures to the enterprise risk register and report them to governance as the deployment scales and changes. Correct
  • DWait until a sensor security incident occurs and then brief governance, because that is the point at which the exposure becomes a confirmed reality.
Emerging technology exposures should be tracked in the risk register and reported to governance as deployment scales, keeping oversight continuous rather than one-off. Adding the sensor exposures to the enterprise risk register and reporting them as the deployment grows creates a continuous, visible link between the changing technology footprint and the people accountable for risk decisions, so oversight keeps pace with the rollout instead of lapsing after a pilot or waiting for an incident to force attention.

Why A is wrong: Closing the risks at pilot end feels tidy, but the exposures persist and scale with the rollout, so a one-off record leaves later decisions uninformed.

Why B is wrong: Vendor expertise is useful, yet delegating the decisions transfers neither accountability nor the enterprise's obligation to manage risk within its own appetite.

Why C is correct: Recording the exposures in the risk register and reporting them as the deployment grows keeps decision makers informed and supports ongoing, risk-based oversight.

Why D is wrong: Briefing only after an incident is purely reactive and denies decision makers the chance to act on the exposure before it is exploited.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Schedule a single penetration test once each release is complete so testers can probe the finished build under realistic conditions.

    Why it is wrong: A late penetration test gives useful assurance, but finding flaws only after the build is finished forces expensive rework and cannot keep pace with daily releases.

  • Storing agreements electronically rather than on paper increases the volume of personal data the organisation must protect from unauthorised access over time.

    Why it is wrong: Greater data volume raises generic confidentiality concerns, but it applies to any digital store and is not the distinctive consequence of choosing an immutable ledger.

  • Block the trial at once and prohibit any use of the service until a full enterprise policy on artificial intelligence has been written and approved.

    Why it is wrong: An immediate ban looks decisive, but acting before understanding the use case ignores potential value and tends to drive the activity into unmanaged shadow usage.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.