IT Risk Management Flashcards
6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 IT Risk Management flashcards as text
An IS auditor is reviewing an organization's IT risk management process. Which of the following is the MOST critical first step in this process?
Answer: Identifying and classifying information assets.
The foundational step in any IT risk management process is to understand what needs to be protected. This involves identifying all information assets and classifying them based on their value and sensitivity to the organization. Without this, it is impossible to effectively assess threats, vulnerabilities, and potential impacts, or to select appropriate risk responses.
During an audit, it is discovered that the organization has not defined its risk appetite. What is the PRIMARY concern for the IS auditor?
Answer: Risk mitigation efforts may not be aligned with business objectives.
Risk appetite is the amount and type of risk that an organization is willing to pursue or retain. Without a clearly defined risk appetite, there is no strategic guidance for making risk-based decisions. This can lead to a misalignment between risk management activities and the organization's strategic goals and objectives, resulting in either excessive risk-taking or overly cautious behavior that stifles innovation.
A company has decided to accept the risk associated with a potential data breach because the cost of the recommended countermeasure exceeds the potential loss. Which of the following risk response strategies has the company adopted?
Answer: Risk Acceptance
Risk acceptance is a strategy where an organization decides to accept a risk's potential consequences without taking further action to reduce it. This is often done when the cost of mitigation outweighs the potential loss, or the risk falls within the defined risk appetite.
Which of the following BEST describes the purpose of a Key Risk Indicator (KRI) in IT risk management?
Answer: To serve as an early warning signal that a risk is emerging or exceeding its threshold.
Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposures in various areas of the enterprise. They are forward-looking and designed to alert management before a risk materializes into a loss event, allowing for proactive risk mitigation.
An IS auditor is evaluating the IT risk assessment process for a financial services company. The auditor finds that the company uses a qualitative approach, categorizing risks as 'High,' 'Medium,' and 'Low.' The PRIMARY disadvantage of this approach is that it:
Answer: makes it difficult to perform a cost-benefit analysis for countermeasures.
A qualitative risk assessment uses subjective judgment to assess the likelihood and impact of risk, often using descriptive categories (e.g., High, Medium, Low). While useful for prioritizing risks, its primary weakness is the lack of quantitative data (e.g., monetary values). This subjectivity makes it difficult to conduct a rigorous cost-benefit analysis when evaluating the financial viability of implementing specific controls.
A software development team is using an Agile methodology. To ensure risk is managed effectively, when should risk management activities be performed?
Answer: Continuously throughout the project lifecycle, especially during sprint planning.
In Agile methodologies, which are iterative and incremental, risk management cannot be a one-time event. It must be an ongoing process that is integrated into the regular project rhythm. Risks should be identified, assessed, and responded to continuously, often as part of sprint planning, daily stand-ups, and retrospectives, to adapt to changing requirements and project conditions.