CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A risk manager is evaluating the effectiveness of security controls for a critical asset. The current controls reduce the likelihood of a successful attack from 80% to 10% and the impact from $1,000,000 to $50,000. What is the residual risk after implementing these controls?

  1. A$80,000
  2. B$5,000
  3. C$500,000
  4. D$800,000
Show answer & explanation

Correct answer: B. $5,000

Residual risk is calculated as the new likelihood multiplied by the new impact. In this case, 10% (0.10) * $50,000 = $5,000. This represents the risk remaining after controls have been applied.

Why the other options are wrong

  • A. This is a plausible distractor, perhaps initial likelihood multiplied by residual impact (0.8 * $50,000).
  • C. This is a plausible distractor, perhaps residual likelihood multiplied by initial impact (0.10 * $1,000,000).
  • D. This is the initial risk (0.8 * $1,000,000).

Residual Risk

The amount of risk that remains after all planned and implemented security controls have been put in place.

  • Calculated as (Likelihood after controls) x (Impact after controls).
  • Cannot be entirely eliminated.
  • Must be accepted by management.

Memory trick: Risk = Likelihood times Impact, after controls it's residual.

More Information Technology and Security questions