Back to Questions
CISA
QUESTION #6868
Question 1
An auditor reviews an organization's risk register and finds that all identified risks are rated as 'Medium' with no High or Low ratings. What does this MOST likely indicate?
Correct Answer Explanation
A risk register where all risks are rated identically provides no useful prioritization. Risk assessment must meaningfully differentiate severity to guide resource allocation and management attention. When everything is 'medium,' management cannot determine what requires immediate attention versus what can be accepted or addressed later.
Sign in to join the conversation and share your thoughts.
Log In to Comment