nerdexam
Isaca

CRISC · Question #362

Which of the following should a risk practitioner do NEXT after learning that Internet of Things (loT) devices installed in the production environment lack appropriate security controls for…

The correct answer is A. Assess the threat and associated impact. After identifying a lack of appropriate security controls for IoT devices handling sensitive data, the next step for a risk practitioner is to assess the potential threats and their associated business impact.

Submitted by fernanda_arg· Apr 18, 2026IT Risk Assessment

Question

Which of the following should a risk practitioner do NEXT after learning that Internet of Things (loT) devices installed in the production environment lack appropriate security controls for sensitive data?

Options

  • AAssess the threat and associated impact.
  • BEvaluate risk appetite and tolerance levels
  • CRecommend device management controls
  • DEnable role-based access control.

How the community answered

(26 responses)
  • A
    69% (18)
  • B
    19% (5)
  • C
    8% (2)
  • D
    4% (1)

Why each option

After identifying a lack of appropriate security controls for IoT devices handling sensitive data, the next step for a risk practitioner is to assess the potential threats and their associated business impact.

AAssess the threat and associated impact.Correct

When a vulnerability (lack of controls) is identified, the immediate next step in the risk management process is to perform a risk assessment. This involves assessing the potential threats that could exploit this vulnerability and the resulting impact on the organization, which helps quantify the risk level.

BEvaluate risk appetite and tolerance levels

Evaluating risk appetite and tolerance levels is part of establishing the risk context, which typically happens before assessing specific risks, or as part of a review after risks are understood.

CRecommend device management controls

Recommending device management controls is a risk treatment step that comes after the risk has been assessed and understood.

DEnable role-based access control.

Enabling role-based access control is a specific control recommendation, which is a risk treatment step, and it may not be the only or most appropriate control without a proper assessment.

Concept tested: Steps in the risk assessment process

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf

Topics

#Risk assessment process#Threat identification#Impact analysis#IoT security

Community Discussion

No community discussion yet for this question.

Full CRISC Practice