CRISC · Question #365
Which of the following is the MOST important reason to restrict access to the risk register on a need- to-know basis?
The correct answer is A. It contains vulnerabilities and threats.. Restricting access to the risk register on a need-to-know basis is most important because it contains sensitive information about an organization's identified vulnerabilities and threats.
Question
Which of the following is the MOST important reason to restrict access to the risk register on a need- to-know basis?
Options
- AIt contains vulnerabilities and threats.
- BThe risk methodology is intellectual property.
- CContents may be used as auditable findings.
- DRisk scenarios may be misinterpreted.
How the community answered
(14 responses)- A93% (13)
- B7% (1)
Why each option
Restricting access to the risk register on a need-to-know basis is most important because it contains sensitive information about an organization's identified vulnerabilities and threats.
The risk register is a critical document that often details an organization's specific vulnerabilities, potential threats, and the likelihood and impact of these risks. Unauthorized access to this information could provide attackers with a roadmap for exploitation, making it essential to protect it on a need-to-know basis.
While the risk methodology might be proprietary, it's generally less sensitive than the actual list of vulnerabilities and threats, and protecting the methodology itself is not the most important reason for restricted access to the register's contents.
Contents being used as auditable findings is a consequence of the risk register's existence and purpose, not the primary reason to restrict access for security.
While misinterpretation of risk scenarios is possible, it is a concern related to communication and training, not the paramount reason for restricting access from a security perspective.
Concept tested: Confidentiality of risk information
Topics
Community Discussion
No community discussion yet for this question.