exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 789 discussion

Actual exam question from Isaca's CRISC
Question #: 789
Topic #: 1
[All CRISC Questions]

Which of the following is the MOST important consideration when determining whether to accept residual risk after security controls have been implemented on a critical system?

  • A. Cost of the information control system.
  • B. Cost versus benefit of additional mitigating controls.
  • C. Annualized loss expectancy (ALE) for the system.
  • D. Frequency of business impact.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
10 months, 3 weeks ago
Selected Answer: B
B. Cost versus benefit of additional mitigating controls. The most important consideration when determining whether to accept residual risk after security controls have been implemented on a critical system is the cost versus the benefit of adding additional mitigating controls. Residual risk represents the level of risk that remains after controls have been applied. It's essential to evaluate whether the cost of implementing additional controls to further reduce this residual risk is justified by the potential benefits and the criticality of the system. While factors like the cost of the information control system, the annualized loss expectancy (ALE), and the frequency of business impact are relevant, they should be considered in the context of whether the cost of additional controls is proportionate to the reduction in risk they provide. This cost-benefit analysis helps organizations make informed decisions about accepting or mitigating residual risk.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: B
Agree it is B.
upvoted 1 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: B
Annualized loss expectancy (ALE) for the system can be a useful metric for assessing the overall risk profile of a critical system, but it is not as helpful as the cost versus benefit analysis in determining whether to accept residual risk or implement additional mitigating controls. ALE provides an estimate of the potential financial impact of a security incident, but it does not take into account the costs associated with implementing additional controls or the potential benefits that those controls could provide.
upvoted 1 times
...
Raj1510
2 years, 6 months ago
ALE determine total maximum amount can be expended to mitigate particular risk. Residual risk (Threats × vulnerability × asset value) × controls gap . Once mitigation of risk performed remaining risk compare against ALE. so will go with C as right answer. If question have talk about additional mitigation we may be consider B.
upvoted 3 times
...
MusMus
2 years, 7 months ago
B makes more sense, it will include the ALE in the BIA
upvoted 2 times
...
BeeSz
3 years, 1 month ago
Can someone explain why C - ALE Is it because you are comparing it to the annual appetite?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...