CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard
A cybersecurity team is conducting a periodic review of the organization's enterprise risk management strategy. They note that the current strategy focuses heavily on identifying and mitigating technical vulnerabilities but lacks clear guidance on how to assess and manage risks associated with human error, supply chain dependencies, and geopolitical events. Which aspect of risk management is primarily deficient?
- AQuantitative Risk Analysis
- BHolistic Risk View
- CTechnical Risk Assessment
- DRisk Mitigation Planning
Show answer & explanationAnswer & explanation
Correct answer: B. Holistic Risk View
The deficiency lies in the strategy's narrow focus on technical vulnerabilities, overlooking broader categories of risk such as human error, supply chain, and geopolitical events. This indicates a lack of a Holistic Risk View, which considers all relevant risk factors across the enterprise.
Why the other options are wrong
- A. Quantitative Risk Analysis is a method of assessing risk, but the issue is the breadth of risk categories considered, not the method of analysis.
- C. Technical Risk Assessment is being performed, but the problem is its limited scope.
- D. Risk Mitigation Planning is a subsequent step after identifying and assessing risks; the problem here is with the scope of identification.
Holistic Risk View
An approach to risk management that considers all types of risks (technical, human, operational, financial, geopolitical, etc.) across the entire organization, recognizing their interdependencies.
- Considers all risk categories.
- Recognizes interdependencies.
- Essential for comprehensive enterprise risk management.
Memory trick: Holistic risk: See the whole picture, not just the tech bits.