CRISC · Question #362
Which of the following should a risk practitioner do NEXT after learning that Internet of Things (loT) devices installed in the production environment lack appropriate security controls for…
The correct answer is A. Assess the threat and associated impact. After identifying a lack of appropriate security controls for IoT devices handling sensitive data, the next step for a risk practitioner is to assess the potential threats and their associated business impact.
Question
Which of the following should a risk practitioner do NEXT after learning that Internet of Things (loT) devices installed in the production environment lack appropriate security controls for sensitive data?
Options
- AAssess the threat and associated impact.
- BEvaluate risk appetite and tolerance levels
- CRecommend device management controls
- DEnable role-based access control.
How the community answered
(26 responses)- A69% (18)
- B19% (5)
- C8% (2)
- D4% (1)
Why each option
After identifying a lack of appropriate security controls for IoT devices handling sensitive data, the next step for a risk practitioner is to assess the potential threats and their associated business impact.
When a vulnerability (lack of controls) is identified, the immediate next step in the risk management process is to perform a risk assessment. This involves assessing the potential threats that could exploit this vulnerability and the resulting impact on the organization, which helps quantify the risk level.
Evaluating risk appetite and tolerance levels is part of establishing the risk context, which typically happens before assessing specific risks, or as part of a review after risks are understood.
Recommending device management controls is a risk treatment step that comes after the risk has been assessed and understood.
Enabling role-based access control is a specific control recommendation, which is a risk treatment step, and it may not be the only or most appropriate control without a proper assessment.
Concept tested: Steps in the risk assessment process
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.