CGRC · Question #322
Which of the following statements correctly describes DIACAP residual risk? Response:
The correct answer is A. It is the remaining risk to the information system after risk palliation has occurred.. DIACAP residual risk refers to the remaining level of risk to an information system after all risk mitigation and palliation efforts have been implemented.
Question
Which of the following statements correctly describes DIACAP residual risk? Response:
Options
- AIt is the remaining risk to the information system after risk palliation has occurred.
- BIt is a process of security authorization.
- CIt is the technical implementation of the security design.
- DIt is used to validate the information system.
How the community answered
(28 responses)- A89% (25)
- B7% (2)
- D4% (1)
Why each option
DIACAP residual risk refers to the remaining level of risk to an information system after all risk mitigation and palliation efforts have been implemented.
Residual risk, in the context of DIACAP or any risk management framework, refers to the inherent risk that remains after an organization has implemented its security controls and risk mitigation strategies. It signifies the acceptable level of remaining risk that the Authorizing Official must formally accept.
Residual risk is a condition or state of risk, not a process of security authorization.
Residual risk is a measurement of remaining risk, not the technical implementation of security design.
Residual risk is what needs to be managed and accepted, not a tool or process used to validate an information system.
Concept tested: DIACAP - Residual Risk definition
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.