CRISC · Question #579
Which of the following BEST enables an organization to address new risk associated with an Internet of Things (IoT) solution?
The correct answer is B. Introducing control procedures early in the life cycle. The most effective way to address new risks from IoT solutions is by integrating control procedures into the solution's design and development during the earliest stages of its lifecycle.
Question
Which of the following BEST enables an organization to address new risk associated with an Internet of Things (IoT) solution?
Options
- ATransferring the risk
- BIntroducing control procedures early in the life cycle
- CUpdating the risk tolerance to include the new risk
- DImplementing IoT device monitoring software
How the community answered
(60 responses)- A15% (9)
- B72% (43)
- C8% (5)
- D5% (3)
Why each option
The most effective way to address new risks from IoT solutions is by integrating control procedures into the solution's design and development during the earliest stages of its lifecycle.
Transferring risk (e.g., via insurance) is a risk treatment option, but it doesn't address the technical risks or vulnerabilities of the IoT solution itself.
Integrating security controls and procedures early in the IoT solution's lifecycle (e.g., during design and development) ensures that security is 'built-in' rather than 'bolted-on.' This approach is more cost-effective, reduces vulnerabilities from the start, and makes the system inherently more resilient to the unique and diverse risks associated with IoT.
Updating risk tolerance simply accepts a higher level of risk; it does not address or mitigate the new risks associated with the IoT solution.
Implementing IoT device monitoring software is a control, but it's reactive or post-deployment. Building controls in early is a more comprehensive and proactive approach to addressing new risks.
Concept tested: IoT risk management strategy
Source: https://learn.microsoft.com/en-us/azure/iot/iot-security-architecture
Topics
Community Discussion
No community discussion yet for this question.