SSCP · Question #1245
When compiling a risk assessment report, which of the following items should be included? (Choose all that apply)
The correct answer is A. Vulnerability levels D. Data sensitivity levels E. ALE calculations. A comprehensive risk assessment report should include vulnerability levels, data sensitivity classifications, and Annualized Loss Expectancy (ALE) calculations to effectively evaluate and present risks.
Question
When compiling a risk assessment report, which of the following items should be included? (Choose all that apply)
Options
- AVulnerability levels
- BMethod of attack used
- CNames of frequent security violators
- DData sensitivity levels
- EALE calculations
How the community answered
(19 responses)- A89% (17)
- B5% (1)
- C5% (1)
Why each option
A comprehensive risk assessment report should include vulnerability levels, data sensitivity classifications, and Annualized Loss Expectancy (ALE) calculations to effectively evaluate and present risks.
Vulnerability levels are essential for a risk assessment report, as they identify the weaknesses that could be exploited and contribute to calculating the likelihood of a risk event.
While knowledge of attack methods is part of identifying threats, a risk assessment report typically focuses on the *potential* for attack, vulnerabilities, and impact, rather than detailing specific methods *used* in past attacks, which would be part of an incident report or threat intelligence.
Including names of frequent security violators in a public or widely distributed risk assessment report is generally not appropriate, as it can raise privacy concerns and is typically handled through internal HR or disciplinary processes, not in the risk assessment itself.
Data sensitivity levels are crucial for a risk assessment report because the potential impact of a security incident depends heavily on the classification and importance of the data involved.
ALE (Annualized Loss Expectancy) calculations provide a quantitative measure of the financial impact of a risk over a year, making them a key component for prioritizing risks in a report.
Concept tested: Risk assessment report components
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-management
Topics
Community Discussion
No community discussion yet for this question.