CRISC - Risk Assessment - Section 2.1

Develop and evaluate IT risk scenarios from risk events, contributing conditions and loss consequences.

Develop IT risk scenarios by pairing threat sources with vulnerabilities and tracing the resulting loss consequences to the organisation. Evaluate each scenario's plausibility so that assessment effort is directed at those with material business impact.

Risk scenariosRisk eventsThreat-vulnerability pairingLoss consequence

Practice question for this objective

Free sampleRisk Assessmenthard

A risk practitioner must rank several disruption scenarios for treatment funding but the organisation has not yet defined formal risk criteria. The practitioner argues that a business impact analysis should be completed first. What is the primary reason a business impact analysis should precede this prioritisation?

  • AIt catalogues the technical controls already protecting each system so that overlapping safeguards can be removed before funding is allocated.
  • BIt calculates the annualised loss expectancy for each scenario so that the residual risk figures can be compared directly against the inherent values.
  • CIt quantifies the operational and financial consequences of disruption over time, supplying the impact criteria needed to rank scenarios objectively. Correct
  • DIt confirms which scenarios the organisation has chosen to accept so that only the unaccepted exposures consume scarce treatment funding.
Understand that a business impact analysis supplies time-based consequence data used as criteria to evaluate and prioritise disruption scenarios. A business impact analysis establishes how disruption consequences escalate over time and which processes are critical, providing the objective impact criteria that scenario prioritisation depends on when formal criteria are otherwise absent.

Why A is wrong: This is tempting because control inventories aid efficiency, but a business impact analysis assesses consequences of disruption, not the catalogue of existing technical safeguards.

Why B is wrong: This is plausible because both involve impact, but annualised loss expectancy is a quantitative analysis technique, whereas a BIA focuses on time-based disruption consequences.

Why C is correct: A business impact analysis measures how consequences grow over time, producing the impact criteria that let scenarios be evaluated and prioritised on a consistent basis.

Why D is wrong: This is attractive because acceptance affects funding, but recording acceptance decisions is a risk response activity, not the purpose of a business impact analysis.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Assessment objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.