712-50 Question 28
Single answerCreate and manage risk registerA newly appointed CISO is standardizing the enterprise risk register after an acquisition. During a steering committee review, business leaders complain that the current register contains hundreds of technical issues, duplicate entries across business units, and little information about who must act on each item. As a result, high-impact risks are not being escalated consistently, and remediation funding is difficult to justify. Which action should the CISO take FIRST to make the risk register an effective decision-support tool for executives and risk owners?
- A
Rebuild the risk register using a standardized taxonomy, defined scoring criteria, clear risk ownership, treatment status, and linkage to business impact
- B
Remove all low and medium risks from the register so executives can focus only on critical issues
- C
Convert every open vulnerability finding from scanning tools into a separate risk entry and report them directly to the board each month
- D
Delay changes to the register until the organization completes a full annual enterprise risk assessment cycle
Show answer and explanation
Correct answer: A
Explanation
The best first action is to redesign the risk register so it consistently captures risk information in a form that supports ownership, prioritization, treatment, and escalation. In practice, mature risk registers include at least: a common risk statement format, category or taxonomy, likelihood and impact criteria, inherent and residual risk where applicable, assigned risk owner, treatment decision, target dates, and business context. This aligns with widely accepted risk-management practices in frameworks such as ISO 31000, which emphasizes structured and comprehensive risk processes, and ISO/IEC 27005, which supports consistent information security risk assessment and treatment. NIST guidance also distinguishes between technical findings and risk decisions, reinforcing that not every vulnerability should become a board-level risk item. Executives need an accurate, normalized register and an appropriately filtered summary view, not a raw collection of technical issues.
- A. Correct.
Correct. A risk register is most effective when it is normalized and structured for governance and decision-making. Standardized taxonomy reduces duplicate and inconsistent entries, defined scoring criteria improves comparability across business units, named risk owners establish accountability, treatment status supports tracking, and linkage to business impact helps leadership prioritize funding and escalation. This is the foundational step before reporting or pruning content.
- B. Incorrect.
Incorrect. While executive reporting should emphasize the most significant risks, deleting lower-rated risks from the register undermines completeness, trend analysis, and accountability. Lower risks may aggregate, change over time, or require acceptance and monitoring. The misconception is confusing the full risk register with an executive summary or dashboard.
- C. Incorrect.
Incorrect. Vulnerabilities are inputs to risk analysis, not automatically stand-alone enterprise risk register items. Creating separate entries for every technical finding would worsen the current problem of excessive volume and poor prioritization. Boards generally require aggregated, business-relevant risk reporting rather than raw operational issue lists.
- D. Incorrect.
Incorrect. Waiting for the next annual assessment delays needed governance improvements and prolongs inconsistent risk handling. A CISO should improve the structure and data quality of the register now so ongoing assessments and reviews produce usable outputs. The misconception is treating the register as a once-a-year artifact instead of a living management tool.