CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A company is developing a risk scenario for 'Unauthorized Access to Sensitive Customer Data via a Vulnerable Web Application Interface'. Which of the following elements BEST represents the 'threat' component of this scenario?

  1. AThe sensitive customer data residing in the backend database.
  2. BThe web application's unpatched SQL injection vulnerability.
  3. CAn external attacker exploiting the vulnerability.
  4. DLoss of customer trust and potential regulatory fines.
Show answer & explanation

Correct answer: C. An external attacker exploiting the vulnerability.

In risk scenarios, the 'threat' refers to the potential cause of an unwanted incident, often represented by an actor (human or natural event) with malicious intent or potential to cause harm. An external attacker is the active agent in this scenario.

Why the other options are wrong

  • A. This describes the 'asset' that is at risk, or the 'target' of the threat.
  • B. This describes a 'vulnerability', which is a weakness that a threat can exploit.
  • D. This describes the 'impact' or 'consequence' of the risk event.

Risk Scenario Components

Key elements that define a risk scenario, typically including threat, vulnerability, asset, and impact.

  • Threat: The potential cause of an incident.
  • Vulnerability: A weakness that can be exploited by a threat.
  • Asset: Something of value that needs protection.

Memory trick: TVA-I: Threats Vandalize Assets, causing Impact.

More IT Risk Assessment questions