What Should a Risk Practitioner Do First During a Cloud-to-On-Prem Migration?
As part of its risk strategy, an organization decided to transition its financial system from a cloud-based provider to an internally managed system. Which of the following should the risk practitioner do FIRST?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization in the risk lifecycle during organizational change, with the common trap being selecting control documentation or testing adjustments before validating the underlying risk posture.
This CRISC question evaluates the correct sequencing of risk management activities during a major infrastructure migration. Community consensus and ISACA guidelines confirm that practitioners must first validate whether existing risk responses remain effective before proceeding to control updates or testing.
Candidates frequently select Option B (analyzing the risk register) or Options A/D (updating controls/testing), mistakenly believing that administrative reviews or procedural tweaks should precede a fundamental reassessment of risk exposure triggered by the architectural shift.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Moving from a cloud provider to an internally managed system fundamentally alters the threat landscape, ownership model, and vulnerability surface. ISACA’s risk management framework dictates that any significant operational change requires an immediate reassessment of how well current risk responses mitigate newly exposed or shifted risks. Until this validation occurs, subsequent control modifications or testing cycles lack a validated foundation.Why the Other Options Are Wrong
Analyzing the risk register (Option B) is a necessary follow-up step but cannot effectively prioritize updates without first understanding how the migration impacts actual risk exposure. Updating control test plans (Option A) or adjusting financial control assessment processes (Option D) are implementation tasks that prematurely assume the original risk responses are still adequate. These actions skip the critical analysis phase required by CRISC methodology.Community Comment Notes
The majority of experienced candidates and commenters strongly endorse Option C, noting that infrastructure transitions inherently invalidate legacy assumptions. Comment [1] correctly highlights that the shift “fundamentally changes the risk landscape,” making response validation the logical starting point. Several users initially debated Option B but agreed that register maintenance follows, rather than precedes, active risk reassessment.Official Reference
Exam Strategy
Always identify the triggering event first; in CRISC, major changes mandate a risk reassessment before touching controls or documentation. When faced with sequential steps, prioritize analytical validation over procedural updates to align with ISACA’s assess-before-implement mindset.
Related Analysis
Practice All CRISC Questions
Access 332 questions with complete answers and detailed explanations.
View Full CRISC Practice Test →