SY0-701 - Security Program Management and Oversight - Section 5.2

Explain elements of the risk management process.

Describe the risk management lifecycle from identification and assessment through treatment and monitoring, and explain how a risk register tracks identified risks alongside their likelihood, impact, and assigned owner. Calculate ALE from SLE and ARO to quantify annualised financial exposure, and apply risk appetite and tolerance thresholds to determine whether a risk should be mitigated, transferred, accepted, or avoided.

risk identificationrisk assessmentrisk registerrisk appetite/toleranceALE/SLE/ARO

Practice question for this objective

Free sampleSecurity Program Management and Oversighthard

A regional building society has just completed its first enterprise risk identification workshop covering its retail banking platform. The chief risk officer wants the output captured in a single, living artefact that records each identified risk, its owner, its current rating, the treatment decision and the residual rating after controls, so that the board can be shown the same view at every quarterly meeting and so that internal audit can trace any individual risk from identification through to its current state. Which artefact most directly meets these requirements?

  • AA business impact analysis spreadsheet that lists each banking process with its recovery time objective and recovery point objective.
  • BA statement of applicability mapping each ISO 27001 Annex A control to whether it has been adopted by the building society.
  • CA risk register that lists each identified risk with its owner, inherent rating, treatment, controls and residual rating. Correct
  • DA plan of action and milestones listing only the open audit findings with target remediation dates and accountable managers.
Identify the risk register as the artefact that records each risk with owner, ratings, treatment and residual rating across its lifecycle. The risk register is the central, living record of identified risks. It carries the per-risk attributes that the risk management process needs to be auditable: owner, inherent rating, controls or treatment, and residual rating after controls. Other artefacts such as the BIA, SoA and POA&M serve adjacent purposes but do not capture the per-risk lifecycle view that the board and internal audit require.

Why A is wrong: A business impact analysis records continuity parameters such as RTO and RPO for processes, not the per-risk owner, treatment and residual rating that the board view requires, so it does not satisfy the artefact need described.

Why B is wrong: A statement of applicability documents which framework controls have been selected and why, but it indexes controls rather than risks and does not carry inherent or residual risk ratings, so it cannot serve as the board-facing per-risk record.

Why C is correct: A risk register is the canonical artefact used to capture identified risks together with ownership, inherent and residual ratings and treatment decisions, which is exactly the running record of the risk lifecycle the chief risk officer described.

Why D is wrong: A plan of action and milestones tracks open findings and their remediation schedule, which is a useful subset, but it does not record every identified risk with its inherent rating, treatment decision and residual rating across the risk lifecycle.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Security Program Management and Oversight objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.