Compliance and Auditing Risk Management 2 — Questions and Answers
Question 1: In IT risk management, what does a Business Impact Analysis (BIA) determine?
- The cost of implementing new technology
- The criticality of business processes and acceptable downtime in the event of disruption (Correct answer)
- Employee productivity metrics
- Return on investment for security controls
Correct answer: The criticality of business processes and acceptable downtime in the event of disruption
A Business Impact Analysis identifies critical business functions, quantifies the impact of disruptions, and determines acceptable recovery time and recovery point objectives.
Question 2: What is the formula for calculating risk in qualitative risk assessment?
- Risk = Threat × Vulnerability
- Risk = Likelihood × Impact (Correct answer)
- Risk = Controls × Assets
- Risk = Cost × Frequency
Correct answer: Risk = Likelihood × Impact
In qualitative risk assessment, risk is typically calculated as the product of the likelihood (probability) of a risk event occurring and the impact (severity) if it does occur.
Question 3: Which three-lines-of-defense model assigns risk management responsibilities to different organizational levels?
- COBIT Framework
- Three Lines of Defense / Three Lines Model (Correct answer)
- COSO Internal Control Framework
- ISO 31000
Correct answer: Three Lines of Defense / Three Lines Model
The Three Lines of Defense (updated to Three Lines Model by IIA in 2020) assigns risk management to: operational management, risk/compliance functions, and internal audit.
Question 4: A vendor risk management program primarily assesses risk from which type of entities?
- Government regulators
- Internal employees
- Third-party suppliers and service providers (Correct answer)
- Shareholders and investors
Correct answer: Third-party suppliers and service providers
Vendor risk management evaluates and monitors risks posed by third-party suppliers, vendors, and service providers who have access to organizational data, systems, or processes.
Question 5: What does RPO (Recovery Point Objective) define in business continuity planning?
- How quickly systems must be restored after a disaster
- The maximum acceptable amount of data loss measured in time (Correct answer)
- The cost of recovering from a disaster
- The geographic location of backup systems
Correct answer: The maximum acceptable amount of data loss measured in time
Recovery Point Objective (RPO) defines the maximum acceptable period of data loss measured in time, determining how frequently data backups must occur.
Question 6: Which risk management standard provides guidelines applicable to any organization regardless of industry?
- NIST SP 800-37
- ISO 31000 (Correct answer)
- PCI DSS
- COBIT 5
Correct answer: ISO 31000
ISO 31000 is an international standard providing principles and guidelines for risk management that can be applied to any organization in any industry or sector.
In IT risk management, what does a Business Impact Analysis (BIA) determine?