Which artifact is a list of risk items that have been identified, analyzed and prioritized?

Prepare for the ISACA IT Risk Fundamentals Test. Find flashcards and multiple choice questions, complete with hints and explanations. Ace your exam with confidence!

Multiple Choice

Which artifact is a list of risk items that have been identified, analyzed and prioritized?

Explanation:
A risk register is the artifact that lists risk items that have been identified, analyzed, and prioritized. It serves as the centralized record where each risk’s description, likelihood, impact, and resulting risk rating are captured, along with owners, actions, and target dates. This enables ongoing monitoring and management of risks as the organization’s risk landscape evolves. Root cause analysis focuses on uncovering underlying causes of incidents rather than cataloging risks. A lag risk indicator is a metric reflecting past conditions or events, not a compiled list of risks. A key risk indicator is a metric used to signal rising risk levels, also not a catalog of identified risks.

A risk register is the artifact that lists risk items that have been identified, analyzed, and prioritized. It serves as the centralized record where each risk’s description, likelihood, impact, and resulting risk rating are captured, along with owners, actions, and target dates. This enables ongoing monitoring and management of risks as the organization’s risk landscape evolves.

Root cause analysis focuses on uncovering underlying causes of incidents rather than cataloging risks. A lag risk indicator is a metric reflecting past conditions or events, not a compiled list of risks. A key risk indicator is a metric used to signal rising risk levels, also not a catalog of identified risks.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy