CRISC - Risk Assessment - Section 2.2

Analyse the threat landscape and apply threat modelling to identify IT risk.

Analyse the current threat landscape by categorising threat sources and mapping attack vectors to organisational assets. Apply threat modelling to structure this analysis so that the highest-priority IT risks are surfaced for assessment.

Threat landscapeThreat modellingThreat sourcesAttack vectors

Practice question for this objective

Free sampleRisk Assessmentmedium

A risk practitioner finds that the enterprise threat landscape is described in a single document that was written two years ago and has not changed since. The board wants the landscape to reflect adversary activity as it evolves. Which practice would MOST reliably keep the threat landscape current?

  • ASchedule a single annual penetration test of the external estate and update the landscape only from its findings.
  • BAsk each system owner to confirm in writing every year that no new threats now apply to their own system.
  • CAdopt a recognised control framework and map each existing control to its relevant clause, section and owner.
  • DFeed continuously updated threat intelligence on relevant actors and campaigns into a regular review of the landscape. Correct
Keeping the threat landscape current depends on a continuous flow of threat intelligence about relevant actors and campaigns, not on periodic snapshots. A threat landscape is only useful while it reflects live adversary activity. Threat intelligence supplies timely external evidence on who is active, what they target and how they operate, allowing the landscape to be refreshed continuously rather than aging into a static snapshot that misses new actors.

Why A is wrong: Annual penetration testing reveals exploitable weaknesses at a point in time, but it is too infrequent and vulnerability-focused to track how adversary behaviour shifts between tests.

Why B is wrong: Periodic owner attestations are easy to collect yet rely on local opinion rather than external evidence, so emerging threat actors and campaigns go unnoticed between cycles.

Why C is wrong: Mapping controls to a framework documents the defensive posture, but it describes what the organisation does and not how the surrounding threat environment is evolving.

Why D is correct: Ongoing threat intelligence about active adversaries, their targets and their methods is the input that lets the landscape be revised as the external environment changes rather than at a fixed date.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Assessment objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.