nerdexam
(ISC)2

CGRC · Question #322

Which of the following statements correctly describes DIACAP residual risk? Response:

The correct answer is A. It is the remaining risk to the information system after risk palliation has occurred.. DIACAP residual risk refers to the remaining level of risk to an information system after all risk mitigation and palliation efforts have been implemented.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following statements correctly describes DIACAP residual risk? Response:

Options

  • AIt is the remaining risk to the information system after risk palliation has occurred.
  • BIt is a process of security authorization.
  • CIt is the technical implementation of the security design.
  • DIt is used to validate the information system.

How the community answered

(28 responses)
  • A
    89% (25)
  • B
    7% (2)
  • D
    4% (1)

Why each option

DIACAP residual risk refers to the remaining level of risk to an information system after all risk mitigation and palliation efforts have been implemented.

AIt is the remaining risk to the information system after risk palliation has occurred.Correct

Residual risk, in the context of DIACAP or any risk management framework, refers to the inherent risk that remains after an organization has implemented its security controls and risk mitigation strategies. It signifies the acceptable level of remaining risk that the Authorizing Official must formally accept.

BIt is a process of security authorization.

Residual risk is a condition or state of risk, not a process of security authorization.

CIt is the technical implementation of the security design.

Residual risk is a measurement of remaining risk, not the technical implementation of security design.

DIt is used to validate the information system.

Residual risk is what needs to be managed and accepted, not a tool or process used to validate an information system.

Concept tested: DIACAP - Residual Risk definition

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Residual Risk#Risk Management#DIACAP#Information System Risk

Community Discussion

No community discussion yet for this question.

Full CGRC Practice