712-50 Question 27
Single answerCreate and manage risk registerA newly appointed CISO is standardizing the enterprise risk register after an internal audit found that business units were tracking cybersecurity risks inconsistently. Some entries listed only technical vulnerabilities, several had no business owner, and many risks remained marked as "open" long after mitigation projects were completed. The board has asked for a register that supports risk-based decision-making, accountability, and periodic reporting. Which action should the CISO take FIRST to improve the quality and usefulness of the risk register?
- A
Require every risk entry to include a clear business impact statement, likelihood and impact rating, risk owner, treatment decision, target review date, and current status
- B
Populate the register immediately with all known vulnerabilities from recent scanner results so leadership has a complete inventory of technical issues
- C
Close any risk items that have associated mitigation projects underway, since active remediation means the risks are already being addressed
- D
Limit the register to high-severity cyber risks only, because lower-rated risks can be handled operationally without executive visibility
Show answer and explanation
Correct answer: A
Explanation
The best first action is to define and enforce minimum data and governance requirements for each risk entry so the register functions as a management tool rather than a disconnected list of technical findings. In mature risk management practice, a risk register should enable identification, analysis, evaluation, treatment, ownership, monitoring, and reporting. This aligns with widely recognized practices in enterprise and information security risk management, including guidance from ISO 31000 and ISO/IEC 27005, which emphasize establishing consistent risk criteria, assigning owners, evaluating impact and likelihood, selecting treatment options, and monitoring risks over time. NIST risk management guidance similarly distinguishes risk from raw vulnerability data and supports documenting risk response, responsible parties, and ongoing review. In this scenario, the audit findings point to missing governance disciplines: lack of business ownership, lack of business context, and poor status management. Standardizing required fields addresses those root causes before the CISO expands reporting or integrates operational data sources.
- A. Correct.
Correct. A useful risk register must support governance and decision-making, not merely catalog issues. Core fields typically include risk description, business impact, likelihood, impact or severity, owner, response or treatment plan, status, and review cadence. Requiring these elements addresses the audit findings directly: it establishes accountability through ownership, enables prioritization through scoring, and improves lifecycle management through status and review dates. This is the foundational first step before expanding or refining the register.
- B. Incorrect.
Incorrect. Vulnerability data can inform risk identification, but a risk register is not the same as a vulnerability inventory. Loading scanner output directly into the register often creates noise, duplicates, and an overly technical view that lacks business context, ownership, and treatment decisions. A CISO may later define criteria for when vulnerabilities should be represented as risks, but standardizing the register structure comes first.
- C. Incorrect.
Incorrect. A mitigation project underway does not mean the underlying risk is no longer present. Until controls are implemented, validated, and residual risk is accepted or reduced to an acceptable level, the risk should remain open or in treatment status. Closing risks prematurely is a common governance failure because it misrepresents exposure and weakens board reporting.
- D. Incorrect.
Incorrect. Executive reporting often emphasizes higher risks, but the enterprise risk register should still reflect the organization's defined risk management criteria and lifecycle, not arbitrarily exclude lower-rated items. Lower risks may aggregate, change over time, or require ownership and monitoring. Excluding them at the outset undermines completeness and can distort trend analysis and treatment tracking.