CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A healthcare provider is developing a new electronic health record (EHR) system. The project manager is conducting a risk assessment and identifies a high probability of data breaches due to vulnerabilities in the system's authentication module. The team proposes implementing multi-factor authentication (MFA) and conducting regular penetration tests. This approach aligns with which of the following risk management principles?

  1. ABe transparent and inclusive.
  2. BIntegrate risk management into organizational processes.
  3. CAddress uncertainty.
  4. DBe dynamic, iterative, and responsive to change.
Show answer & explanation

Correct answer: B. Integrate risk management into organizational processes.

Implementing MFA and penetration tests as part of the EHR system development demonstrates that risk management is not a standalone activity but is being built into the project and system development lifecycle, which aligns with integrating risk management into organizational processes.

Why the other options are wrong

  • A. Transparency and inclusivity are important principles but not directly demonstrated by the technical controls chosen.
  • C. While risk management addresses uncertainty, this option is too general; the scenario describes a specific action of integration.
  • D. While risk management is dynamic, the scenario describes initial integration rather than a response to a change or iteration.

Integrate Risk Management

A principle stating that risk management should be embedded into all organizational processes, decision-making, and structures, rather than being a separate or isolated activity.

  • Risk considerations are part of daily operations.
  • Not a 'bolt-on' activity.
  • Ensures proactive risk treatment.

Memory trick: Risk is Integrated, Structured, Tailored, Inclusive, Dynamic, Best Available, Human, and Continually Improved.

More Information Technology and Security questions