CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A risk manager is evaluating the effectiveness of security controls for a critical asset. The current controls reduce the likelihood of a successful attack from 80% to 10% and the impact from $1,000,000 to $50,000. What is the residual risk after implementing these controls?
- A$80,000
- B$5,000
- C$500,000
- D$800,000
Show answer & explanationAnswer & explanation
Correct answer: B. $5,000
Residual risk is calculated as the new likelihood multiplied by the new impact. In this case, 10% (0.10) * $50,000 = $5,000. This represents the risk remaining after controls have been applied.
Why the other options are wrong
- A. This is a plausible distractor, perhaps initial likelihood multiplied by residual impact (0.8 * $50,000).
- C. This is a plausible distractor, perhaps residual likelihood multiplied by initial impact (0.10 * $1,000,000).
- D. This is the initial risk (0.8 * $1,000,000).
Residual Risk
The amount of risk that remains after all planned and implemented security controls have been put in place.
- Calculated as (Likelihood after controls) x (Impact after controls).
- Cannot be entirely eliminated.
- Must be accepted by management.
Memory trick: Risk = Likelihood times Impact, after controls it's residual.