CISM · Question #713
A risk assessment of a custom application was performed during the design phase. After the application goes live, which of the following circumstances would MOST likely require a risk reassessment?
The correct answer is C. Additional functions are proposed. A risk assessment is tied to the scope and functionality of a system at a point in time. When additional functions are proposed, the application's attack surface, data flows, trust boundaries, and threat model all potentially change - warranting a fresh risk assessment before…
Question
A risk assessment of a custom application was performed during the design phase. After the application goes live, which of the following circumstances would MOST likely require a risk reassessment?
Options
- AA patch is applied to the application server
- BProcedures are changing
- CAdditional functions are proposed
- DSecurity staff is changing
How the community answered
(40 responses)- A13% (5)
- B8% (3)
- C78% (31)
- D3% (1)
Explanation
A risk assessment is tied to the scope and functionality of a system at a point in time. When additional functions are proposed, the application's attack surface, data flows, trust boundaries, and threat model all potentially change - warranting a fresh risk assessment before those changes are implemented. Option A (a patch applied to the server) is routine maintenance that reduces risk rather than introducing new risk and does not normally require reassessment. Option B (changing procedures) is an operational change that may trigger a review but is less likely to fundamentally alter the application's risk profile. Option D (changing security staff) is a personnel/organizational change, not a change to the system itself.
Topics
Community Discussion
No community discussion yet for this question.