CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A healthcare provider is developing a new electronic health record (EHR) system. The project manager is conducting a risk assessment and identifies a high probability of data breaches due to vulnerabilities in the system's authentication module. The team proposes implementing multi-factor authentication (MFA) and conducting regular penetration tests. This approach aligns with which of the following risk management principles?
- ABe transparent and inclusive.
- BIntegrate risk management into organizational processes.
- CAddress uncertainty.
- DBe dynamic, iterative, and responsive to change.
Show answer & explanationAnswer & explanation
Correct answer: B. Integrate risk management into organizational processes.
Implementing MFA and penetration tests as part of the EHR system development demonstrates that risk management is not a standalone activity but is being built into the project and system development lifecycle, which aligns with integrating risk management into organizational processes.
Why the other options are wrong
- A. Transparency and inclusivity are important principles but not directly demonstrated by the technical controls chosen.
- C. While risk management addresses uncertainty, this option is too general; the scenario describes a specific action of integration.
- D. While risk management is dynamic, the scenario describes initial integration rather than a response to a change or iteration.
Integrate Risk Management
A principle stating that risk management should be embedded into all organizational processes, decision-making, and structures, rather than being a separate or isolated activity.
- Risk considerations are part of daily operations.
- Not a 'bolt-on' activity.
- Ensures proactive risk treatment.
Memory trick: Risk is Integrated, Structured, Tailored, Inclusive, Dynamic, Best Available, Human, and Continually Improved.