CISA · Question #81
An organization's IT risk assessment should include the identification of:
The correct answer is A. vulnerabilities. An IT risk assessment fundamentally involves identifying weaknesses or flaws within systems and processes that could be exploited.
Question
An organization’s IT risk assessment should include the identification of:
Options
- Avulnerabilities
- Bcompensating controls
- Cbusiness process owners
- Dbusiness needs
How the community answered
(46 responses)- A91% (42)
- B4% (2)
- C2% (1)
- D2% (1)
Why each option
An IT risk assessment fundamentally involves identifying weaknesses or flaws within systems and processes that could be exploited.
Vulnerabilities are weaknesses that could be exploited by threats to cause harm, and identifying these is a core component of a risk assessment to understand potential points of failure or attack. Without knowing the vulnerabilities, an organization cannot accurately assess the likelihood or impact of a risk event.
Compensating controls are implemented *after* risks are identified to mitigate them, not identified *as part of* the initial risk identification phase.
Business process owners are individuals responsible for processes, but their identification is not a direct output of the technical risk assessment itself, though they may provide input.
Business needs define the objectives and requirements, which inform the scope of the risk assessment, but are not direct 'identifications' within the assessment's core findings of risk elements.
Concept tested: IT risk assessment components
Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-assessment
Topics
Community Discussion
No community discussion yet for this question.