CRISC · Question #311
An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?
The correct answer is C. Inherent risk. Accepting credit card payments introduces new vulnerabilities and sensitive data handling requirements, directly increasing the organization's inherent risk before any security measures are applied.
Question
An organization has just started accepting credit card payments from customers via the corporate website. Which of the following is MOST likely to increase as a result of this new initiative?
Options
- ARisk tolerance
- BRisk appetite
- CInherent risk
- DResidual risk
How the community answered
(25 responses)- A8% (2)
- C80% (20)
- D12% (3)
Why each option
Accepting credit card payments introduces new vulnerabilities and sensitive data handling requirements, directly increasing the organization's inherent risk before any security measures are applied.
Risk tolerance is the acceptable deviation around risk appetite and is a measure of an organization's willingness to take on risk, not a direct consequence of a new operational initiative.
Risk appetite is the total amount and type of risk an organization is willing to pursue or retain to achieve its objectives, which is a strategic decision and not automatically increased by a new operational initiative.
Inherent risk is the level of risk present before any controls or mitigations are in place; accepting credit card payments directly introduces new types of threats and vulnerabilities, such as data breaches and fraud, associated with handling financial data, thereby increasing the baseline risk.
Residual risk is the risk remaining after controls have been implemented; an increase in inherent risk may lead to an increase in residual risk if controls are insufficient, but inherent risk is the initial and most direct increase.
Concept tested: Inherent vs. Residual Risk
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/reference/nfa-security#risk-definitions
Topics
Community Discussion
No community discussion yet for this question.