CRISC - Risk Assessment (22% of the exam) - Section 2.5

Select risk assessment concepts, standards and frameworks appropriate to the organisation.

Compare risk assessment standards and frameworks - including ISO 31000 and NIST risk frameworks - across their scope, terminology, and assessment methods. Select the approach that best fits the organisation's industry, regulatory context, and risk management maturity.

Risk assessment standardsISO 31000NIST risk frameworksAssessment methods

Practice question for this objective

Free sampleRisk Assessmentmedium

A multinational retailer already certified to ISO 27001 wants to adopt a risk assessment standard that integrates cleanly with its existing information security management system without introducing a conflicting risk vocabulary. Which standard is the most appropriate choice?

  • AISO 27005, because it provides information security risk guidance designed to support the ISO 27001 management system already in place. Correct
  • BFAIR, because it supplies a taxonomy for quantifying cyber loss that can replace the existing management system risk process.
  • COCTAVE Allegro, because it offers a self-directed workshop method that operates independently of any existing management system.
  • DPCI DSS, because it defines a prescriptive control baseline that the retailer can substitute for its current risk process.
Select ISO 27005 as the risk assessment standard that aligns with and supports an existing ISO 27001 information security management system. ISO 27005 was written specifically to provide information security risk management guidance consistent with ISO 27001, so adopting it reuses the same terminology and process rather than imposing a competing risk vocabulary.

Why A is correct: ISO 27005 is purpose-built to support an ISO 27001 information security management system, so its terms and process align with the retailer's existing certification.

Why B is wrong: It is tempting as a quantification model, but positioning it to replace the existing process introduces the very vocabulary conflict the retailer wants to avoid.

Why C is wrong: It is plausible as an established assessment method, yet its self-directed approach sits apart from ISO and does not integrate with the certified management system.

Why D is wrong: It is attractive given the retail payment context, but PCI DSS is a control mandate for card data, not a risk assessment standard that integrates with ISO 27001.

See more CRISC practice questions, answers explained.

Exam traps in Risk Assessment

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • NIST SP 800-30, because it gives a structured guide for conducting IT system risk assessments and threat-source tables.

    Why it is wrong: It is tempting because it is a respected risk assessment guide, but it is scoped to information system risk and does not provide an enterprise-wide principles and governance framework.

  • The principles component, which states the value-creating characteristics that effective risk management should display across the whole organisation.

    Why it is wrong: The principles describe the qualities effective risk management should exhibit, such as being integrated and structured, but they state intent rather than the governance and organisational arrangements that embed practice, so they do not resolve the structural gap.

  • The residual risk of each system, because the exposure remaining after controls operate is the figure that should always determine which system is reviewed before any others.

    Why it is wrong: Residual risk is the right basis for evaluating acceptability, but it cannot drive this decision because control effectiveness has not yet been established for the systems in question.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.