nerdexam
Isaca

CISM · Question #713

A risk assessment of a custom application was performed during the design phase. After the application goes live, which of the following circumstances would MOST likely require a risk reassessment?

The correct answer is C. Additional functions are proposed. A risk assessment is tied to the scope and functionality of a system at a point in time. When additional functions are proposed, the application's attack surface, data flows, trust boundaries, and threat model all potentially change - warranting a fresh risk assessment before…

Submitted by asante_acc· Apr 18, 2026Information Security Risk Management

Question

A risk assessment of a custom application was performed during the design phase. After the application goes live, which of the following circumstances would MOST likely require a risk reassessment?

Options

  • AA patch is applied to the application server
  • BProcedures are changing
  • CAdditional functions are proposed
  • DSecurity staff is changing

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    78% (31)
  • D
    3% (1)

Explanation

A risk assessment is tied to the scope and functionality of a system at a point in time. When additional functions are proposed, the application's attack surface, data flows, trust boundaries, and threat model all potentially change - warranting a fresh risk assessment before those changes are implemented. Option A (a patch applied to the server) is routine maintenance that reduces risk rather than introducing new risk and does not normally require reassessment. Option B (changing procedures) is an operational change that may trigger a review but is less likely to fundamentally alter the application's risk profile. Option D (changing security staff) is a personnel/organizational change, not a change to the system itself.

Topics

#Risk Reassessment#Change Management#Application Risk#Risk Triggers

Community Discussion

No community discussion yet for this question.

Full CISM Practice