CISM · Question #103
When reporting information security risk to senior management, it is MOST important to include:
The correct answer is D. residual risk.. When reporting information security risk to senior management, it is most crucial to communicate the residual risk, as this represents the current level of risk remaining after controls have been implemented.
Question
When reporting information security risk to senior management, it is MOST important to include:
Options
- Acontrol risk.
- Binherent risk.
- Cdetection risk.
- Dresidual risk.
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C5% (1)
- D81% (17)
Why each option
When reporting information security risk to senior management, it is most crucial to communicate the residual risk, as this represents the current level of risk remaining after controls have been implemented.
Control risk refers to the risk that a control fails to prevent or detect a misstatement, which is an input to assessing inherent and residual risk, but not the final picture for management.
Inherent risk is the risk before any controls are put in place, which is useful for initial assessment but doesn't reflect the current state for management decision-making.
Detection risk is the risk that an auditor will not detect a material misstatement, primarily relevant to audit processes rather than the ongoing operational risk reporting to management.
When reporting information security risk to senior management, it is most important to include residual risk because this figure represents the current level of risk remaining after all implemented controls have been considered. Senior management needs to understand the actual exposure and potential impact to the business that persists, enabling them to make informed decisions about further mitigation or risk acceptance.
Concept tested: Risk reporting to senior management
Topics
Community Discussion
No community discussion yet for this question.