The correct answer is D . Without architecture documentation, the organization may not know all systems, interfaces, dependencies, trust boundaries, data flows, or exposed components. This creates unknown vulnerabilities and weakens risk assessment. The uploaded CRISC notes state that understanding the system and its subsystems is the most effective method to conduct a risk assessment on an internal system. They also state that analysts use organizational structure, policies, standards, technology architecture, and controls criteria to analyze risk scenarios.
Legacy systems, scalability issues, and network isolation problems may exist, but the greatest risk from missing architecture documentation is not knowing where the vulnerabilities are.
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit