CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentEasy

A financial institution is evaluating the risk associated with a new mobile banking application. During the risk identification phase, the team considers potential vulnerabilities in the application's code, the underlying operating system, and the network infrastructure. Which of the following risk identification techniques is being primarily applied in this scenario?

  1. AThreat Modeling
  2. BRisk Checklists
  3. CBrainstorming
  4. DDelphi Technique
Show answer & explanation

Correct answer: A. Threat Modeling

Threat modeling systematically analyzes a system's architecture to identify potential threats and vulnerabilities. By examining the application's components and their interactions, the team is proactively looking for weaknesses that could be exploited.

Why the other options are wrong

  • B. Risk checklists rely on predefined lists of risks, whereas this scenario describes a more in-depth architectural analysis.
  • C. Brainstorming is a free-form idea generation, not a structured architectural analysis.
  • D. Delphi technique uses expert consensus through iterative surveys, which is not described here.

Threat Modeling

A structured approach to identify potential threats, vulnerabilities, and attacks against a system or application during its design or development phase.

  • Focuses on system architecture and data flow.
  • Proactive rather than reactive.
  • Helps prioritize security efforts.

Memory trick: Imagine a detective modeling a crime scene to find all the possible threats.

More IT Risk Assessment questions