CRISC · Question #426
Which of the following changes would be reflected in an organization's risk profile after the failure of a critical patch implementation?
The correct answer is D. Residual risk is increased. The failure of a critical patch implementation directly increases the organization's residual risk, as the intended control did not effectively mitigate the vulnerability.
Question
Which of the following changes would be reflected in an organization's risk profile after the failure of a critical patch implementation?
Options
- ARisk appetite is decreased.
- BInherent risk is increased.
- CRisk tolerance is decreased.
- DResidual risk is increased.
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C8% (3)
- D84% (32)
Why each option
The failure of a critical patch implementation directly increases the organization's residual risk, as the intended control did not effectively mitigate the vulnerability.
Risk appetite is a strategic decision about the amount of risk an organization is willing to take, which is not directly altered by a single operational control failure.
Inherent risk is the risk level before any controls are applied; the patch failure affects the effectiveness of an implemented control, not the baseline inherent risk.
Risk tolerance defines acceptable variation around the risk appetite and is a strategic setting, not directly changed by the operational failure of a patch.
Residual risk is the risk that remains after controls have been implemented and are operating. When a critical patch implementation fails, the intended control against a vulnerability is ineffective, leaving the system exposed and directly increasing the amount of remaining, unmitigated risk, thereby raising the residual risk.
Concept tested: Residual risk definition and impact of control failure
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-6-perform-risk-assessments-and-reviews
Topics
Community Discussion
No community discussion yet for this question.