CGRC · Question #221
Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the diffe
The correct answer is B. Human interaction C. Equipment malfunction D. Inside and outside attacks E. Social status F. Physical damage. Information risk management involves identifying and reducing various types of risks that can affect an organization's systems and data. These categories encompass human factors, equipment issues, malicious attacks, and physical threats to infrastructure.
Question
Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the different categories of risk? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- ASystem interaction
- BHuman interaction
- CEquipment malfunction
- DInside and outside attacks
- ESocial status
- FPhysical damage
How the community answered
(14 responses)- A7% (1)
- B93% (13)
Why each option
Information risk management involves identifying and reducing various types of risks that can affect an organization's systems and data. These categories encompass human factors, equipment issues, malicious attacks, and physical threats to infrastructure.
System interaction itself is not a distinct category of risk but rather a context within which other risks, like system malfunction or attacks, might manifest.
Human interaction is a key risk category as human errors, negligence, or malicious intent can directly compromise information security, leading to breaches or system failures.
Equipment malfunction poses a significant risk due to hardware failures or software bugs that can lead to system unavailability, data corruption, or operational disruptions.
Inside and outside attacks are critical risk categories, representing both internal threats (insiders) and external threats (cyberattacks, espionage) aiming to exploit vulnerabilities for unauthorized access or disruption.
Social status, often referring to social engineering, is a common risk category where attackers manipulate individuals into divulging confidential information or performing actions that compromise security.
Physical damage, such as natural disasters, accidents, or deliberate sabotage, directly threatens the physical infrastructure supporting information systems and data, leading to loss or unavailability.
Concept tested: Information risk categories
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.