CAS-002 · Question #603
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers…
The correct answer is A. The resulting impact of even one attack being realized might cripple the company financially. Risk analysis requires evaluating both likelihood AND impact - a low probability event with catastrophic potential consequences still represents significant risk that demands scrutiny.
Question
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers plan to bring on-line in three weeks. The director begins by reviewing the thorough and well-written report from the independent contractor who performed a security assessment of the system. The report details what seems to be a manageable volume of infrequently exploited security vulnerabilities. The likelihood of a malicious attacker exploiting one of the vulnerabilities is low; however, the director still has some reservations about approving the system because of which of the following?
Options
- AThe resulting impact of even one attack being realized might cripple the company financially.
- BGovernment health care regulations for the pharmaceutical industry prevent the director from
- CThe director is new and is being rushed to approve a project before an adequate assessment
- DThe director should be uncomfortable accepting any security vulnerabilities and should find
How the community answered
(44 responses)- A70% (31)
- B16% (7)
- C9% (4)
- D5% (2)
Why each option
Risk analysis requires evaluating both likelihood AND impact - a low probability event with catastrophic potential consequences still represents significant risk that demands scrutiny.
In formal risk analysis, risk is calculated as the product of likelihood and impact. A pharmaceutical company holds sensitive intellectual property, regulated patient-related data, and operates under strict FDA and other health regulations. Even a single successful exploit of a low-probability vulnerability could trigger regulatory sanctions, expose trade secrets, or halt production, resulting in devastating financial and reputational damage that outweighs the low likelihood estimate.
This answer suggests an external regulatory prohibition prevents approval, but the scenario describes the director's own reservations about residual risk - not a compliance mandate blocking sign-off.
While being new and rushed is a practical concern, it does not represent the core technical or risk-based reason to withhold approval - the director's concern is about the potential severity of realized threats.
Requiring zero vulnerabilities before approval is an unachievable standard in any real system and does not reflect accepted risk management frameworks, which focus on risk tolerance and residual risk acceptance.
Concept tested: Risk assessment - likelihood versus impact analysis
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.