CRISC · Question #368
A key risk indicator (KRI) that incorporates data from external open-source threat intelligence sources has shown changes in risk trend dat
The correct answer is B. Impact of risk occurrence. When a Key Risk Indicator (KRI) incorporating external threat intelligence shows changes in risk trend data, it is most important to update the impact of risk occurrence in the risk register.
Question
A key risk indicator (KRI) that incorporates data from external open-source threat intelligence sources has shown changes in risk trend dat
Options
- AWhich of the following is MOST important to update in the risk register?
- BImpact of risk occurrence
- CFrequency of risk occurrence
- DCost of risk response
- ELegal aspects of risk realization
How the community answered
(46 responses)- A15% (7)
- B74% (34)
- C2% (1)
- D4% (2)
- E4% (2)
Why each option
When a Key Risk Indicator (KRI) incorporating external threat intelligence shows changes in risk trend data, it is most important to update the impact of risk occurrence in the risk register.
Key Risk Indicators (KRIs) incorporating external threat intelligence often highlight changes in the potential severity or consequences of a risk event. For example, new attack techniques or vulnerabilities revealed by threat intelligence might indicate that a successful attack could now cause a greater level of data loss, system downtime, or financial damage than previously estimated, thereby directly affecting the impact of risk occurrence.
While threat intelligence can also influence the frequency of risk occurrence, the impact (the potential harm) is often the most critical factor to update if the nature of the threat or its potential consequences have evolved significantly.
The cost of risk response refers to the expenses associated with implementing controls or mitigation actions, which is a separate consideration from the inherent impact of the risk itself.
Legal aspects of risk realization would be reviewed if a risk event occurred and caused legal repercussions, but it's not the primary update based on trend data from threat intelligence.
Concept tested: Updating risk register based on KRI and threat intelligence
Topics
Community Discussion
No community discussion yet for this question.