CRISC - Risk Response and Reporting - Section 3.7

Implement controls and integrate them into business processes and the technology environment.

Implement controls by integrating them into business processes and the technology environment so they operate reliably rather than in isolation. Apply a defence in depth approach to layer multiple controls against each significant risk, reducing reliance on any single control objective.

Control implementationProcess integrationControl objectivesDefence in depth

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A risk practitioner is implementing controls to protect privileged administrative access to a core finance system, applying defence in depth so the objective is not lost if one safeguard fails. Which implementation approach best reflects defence in depth for this objective?

  • ADeploy the strongest available multi-factor authentication mechanism and concentrate the implementation effort on hardening that single control thoroughly
  • BPlace a network firewall in front of the finance system so that all privileged access traffic must first pass through the perimeter device
  • CSchedule a quarterly review of privileged accounts so any inappropriate access is detected and removed within the following review cycle
  • DCombine multi-factor authentication, just-in-time access approval and independent session logging so a failure in one layer does not by itself grant uncontrolled access Correct
Apply defence in depth by layering preventive, approval and detective controls so no single failure leaves a critical objective unprotected. Defence in depth means no single control failure should compromise the objective. For privileged administrative access, combining a preventive authentication control, a just-in-time approval gate and independent session logging creates overlapping layers, so a weakness in one is contained by the others. Concentrating on one strong control, a single perimeter device, or a periodic review alone all reintroduce a single point of failure, which is the opposite of what defence in depth is designed to prevent.

Why A is wrong: Investing heavily in one strong control is tempting, but defence in depth specifically avoids relying on a single layer, since its failure would then leave the objective exposed.

Why B is wrong: A perimeter firewall is one useful layer, but resting the whole objective on a single network control repeats the single-point-of-failure weakness defence in depth is meant to remove.

Why C is wrong: Periodic review is a valuable detective layer, but on its own it allows misuse to persist until the next cycle and does not provide the preventive depth the objective needs.

Why D is correct: Layering authentication, approval and monitoring controls means no single failure leaves privileged access uncontrolled, which is exactly what defence in depth seeks for a critical objective.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Response and Reporting objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.