CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentEasy

A financial institution is implementing a new online banking platform. During the IT risk identification phase, the risk manager needs to ensure all potential threats and vulnerabilities are considered. Which of the following techniques is MOST effective for identifying novel and emerging risks that may not be apparent from historical data?

  1. AReviewing past audit reports and incident logs.
  2. BAnalyzing industry best practices and regulatory compliance documents.
  3. CConducting a structured brainstorming session with cross-functional experts.
  4. DPerforming a vulnerability scan on the new platform's infrastructure.
Show answer & explanation

Correct answer: C. Conducting a structured brainstorming session with cross-functional experts.

Structured brainstorming with cross-functional experts is highly effective for identifying novel and emerging risks because it leverages diverse perspectives and creative thinking, going beyond historical data or known vulnerabilities.

Why the other options are wrong

  • A. Past audit reports and incident logs are useful for known risks but less effective for novel or emerging threats.
  • B. Industry best practices and regulations address established risks, not necessarily novel ones.
  • D. Vulnerability scans identify technical flaws, which are a subset of all potential risks and don't cover emerging business or process risks.

Risk Identification Techniques

Methods used to discover, recognize, and describe risks that could affect an organization's objectives.

  • Aims to be comprehensive and systematic.
  • Combines historical analysis with forward-looking approaches.
  • Involves various stakeholders and perspectives.

Memory trick: Identify ALL risks, known and unknown, like a detective with a magnifying glass.

More IT Risk Assessment questions