Isaca Certified in Risk and Information Systems Control CRISC Question # 326 Topic 33 Discussion
CRISC Exam Topic 33 Question 326 Discussion:
Question #: 326
Topic #: 33
An updated report from a trusted research organization shows that attacks have increased in the organization's industry segment. What should be done FIRST to integrate this data into risk assessments?
A.
Average the ransomware attack frequencies together
B.
Revise the threat frequency for ransomware attack types
C.
Adjust impact amounts based on the average ransom
D.
Use the new frequency as the maximum value in a Monte Carlo simulation
New threat intelligence primarily impacts the frequency component of risk calculations.
CRISC states:
“When new information about threats is available, it must be incorporated into risk assessment by adjusting threat event frequencies in related scenarios.”
A and D are statistical manipulations, not practical first steps.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit