Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CRISC topic 1 question 872 discussion

Actual exam question from Isaca's CRISC
Question #: 872
Topic #: 1
[All CRISC Questions]

An IT risk practitioner has been asked to regularly report on the overall status and effectiveness of the IT risk management program. Which of the following is
MOST useful for this purpose?

  • A. Capability maturity level
  • B. Balanced scorecard
  • C. Control self-assessment (CSA)
  • D. Internal audit plan
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
01010100
6 months, 2 weeks ago
Selected Answer: A
A. Capability maturity level The Capability Maturity Model (often used in its Integrated form, CMMI) provides a structured approach for assessing and improving processes within an organization. By evaluating the maturity level of the processes, the organization can get a clear view of the current state, effectiveness, and maturity of its IT risk management program. Option B, "Balanced scorecard," is a strategic performance management tool that looks at a variety of indicators across different organizational perspectives, but it may not provide a detailed view of the IT risk management program's maturity and effectiveness. Option C, "Control self-assessment (CSA)," provides a way for organizations to assess the effectiveness of their controls, but it doesn't provide a comprehensive view of the IT risk management program's maturity. Option D, "Internal audit plan," provides a schedule and scope for internal audits but doesn't provide a comprehensive assessment of the maturity and effectiveness of the IT risk management program. Thus, assessing the capability maturity level would be the most useful method for regularly reporting on the overall status and effectiveness of the IT risk management program.
upvoted 1 times
...
Staanlee
7 months, 1 week ago
Selected Answer: B
B. Balanced scorecard The balanced scorecard is MOST useful for regularly reporting on the overall status and effectiveness of the IT risk management program. The balanced scorecard is a strategic performance management framework that provides a balanced view of an organization's performance across multiple dimensions, including financial, customer, internal processes, and learning and growth.
upvoted 1 times
...
CbtL
1 year ago
Selected Answer: B
Agree with B.
upvoted 1 times
...
Koulyo
1 year ago
I will go with Balanced score card. The language in the stupid ISACA manual is intentionally made convoluted.
upvoted 2 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: B
From the self-assessment questions (7th CRISC manual, chapter 3), 'a scorecard allows management to measure strategy implementation and assist management in translating it into action'.
upvoted 2 times
...
Suchib
1 year, 3 months ago
In the CRISC manual have never came across scorecard, is it something being used to asses risk assessment process or framework?
upvoted 1 times
CbtL
1 year ago
7th Edition Review Manual, 3.13.2 Scorecards.
upvoted 1 times
...
...
AllaAlla
2 years, 1 month ago
also agree with this answer. scorecard is most suitable in this situation
upvoted 3 times
...
Raj1510
2 years, 3 months ago
I think scorecard is right here. CMM generally used when compare with peer organization or gap analysis. Scorecard is kind academic report of individual in different areas of company like finance, process, customers etc.
upvoted 3 times
...
ohamdan
2 years, 10 months ago
I think the correct answer is A. Capability maturity level
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...