Which artifact is a list of risk items that have been identified, analyzed and prioritized?

Master the ISACA IT Risk Fundamentals Exam. Use flashcards and multiple-choice questions with hints and explanations. Prepare effectively for your certification!

Multiple Choice

Which artifact is a list of risk items that have been identified, analyzed and prioritized?

Explanation:
A risk register is the artifact that lists risk items that have been identified, analyzed, and prioritized. It serves as the centralized record where each risk’s description, likelihood, impact, and resulting risk rating are captured, along with owners, actions, and target dates. This enables ongoing monitoring and management of risks as the organization’s risk landscape evolves. Root cause analysis focuses on uncovering underlying causes of incidents rather than cataloging risks. A lag risk indicator is a metric reflecting past conditions or events, not a compiled list of risks. A key risk indicator is a metric used to signal rising risk levels, also not a catalog of identified risks.

A risk register is the artifact that lists risk items that have been identified, analyzed, and prioritized. It serves as the centralized record where each risk’s description, likelihood, impact, and resulting risk rating are captured, along with owners, actions, and target dates. This enables ongoing monitoring and management of risks as the organization’s risk landscape evolves.

Root cause analysis focuses on uncovering underlying causes of incidents rather than cataloging risks. A lag risk indicator is a metric reflecting past conditions or events, not a compiled list of risks. A key risk indicator is a metric used to signal rising risk levels, also not a catalog of identified risks.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy