CGRC · Question #684
Which of the following relations correctly describes residual risk? Response:
The correct answer is D. Residual Risk = Threats x Vulnerability x Asset Value x Control Gap. Residual risk is the remaining risk after security controls have been implemented, commonly calculated by considering threats, vulnerabilities, asset value, and the effectiveness of existing controls.
Question
Which of the following relations correctly describes residual risk? Response:
Options
- AResidual Risk = Threats x Vulnerability x Asset Gap x Control Gap
- BResidual Risk = Threats x Exploit x Asset Value x Control Gap
- CResidual Risk = Threats x Exploit x Asset Value x Control Gap
- DResidual Risk = Threats x Vulnerability x Asset Value x Control Gap
How the community answered
(41 responses)- A2% (1)
- B5% (2)
- C2% (1)
- D90% (37)
Why each option
Residual risk is the remaining risk after security controls have been implemented, commonly calculated by considering threats, vulnerabilities, asset value, and the effectiveness of existing controls.
The term 'Asset Gap' is not standard in common risk calculation formulas for residual risk.
'Exploit' is a component of a threat or vulnerability, not typically a standalone multiplier in the overarching risk formula.
'Exploit' is a component of a threat or vulnerability, not typically a standalone multiplier in the overarching risk formula.
Residual risk is the risk that remains after all security controls have been implemented and exercised. A common conceptual formula for risk includes threats, vulnerabilities, and asset value, with the 'control gap' implicitly or explicitly representing the remaining exposure after controls are applied.
Concept tested: Residual Risk Calculation Formula
Source: https://csrc.nist.gov/glossary/term/residual_risk
Topics
Community Discussion
No community discussion yet for this question.