SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

A company is performing its annual security audit. An auditor notes that the organization has a comprehensive incident response plan, but it has not been tested or updated in the past three years, despite significant changes in the IT infrastructure and business processes. This situation primarily represents which type of risk?

  1. ACompliance risk
  2. BStrategic risk
  3. CReputational risk
  4. DOperational risk
Show answer & explanation

Correct answer: D. Operational risk

Operational risk refers to risks associated with the day-to-day operations of an organization, including failures in processes, systems, or people. An outdated and untested incident response plan directly impacts the company's ability to effectively manage security incidents, which is a core operational function. This failure in a critical process leads to operational risk.

Why the other options are wrong

  • A. While there might be compliance implications, the primary issue is the operational failure to maintain a functional incident response.
  • B. Strategic risk relates to high-level business objectives and decisions, not the execution of a specific IT security process.
  • C. Reputational risk is a consequence of an incident, not the underlying weakness in the incident response process itself.

Operational Risk

The risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.

  • Includes risks related to IT system failures, human error, and process breakdowns.
  • Distinguished from strategic, financial, or reputational risks.
  • A key area for security management as many security failures stem from operational issues.

Memory trick: Strategic for goals, Operational for daily work, Financial for money, Compliance for rules, Reputational for image.

More Risk Identification, Monitoring, and Analysis questions