CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A project manager is reviewing the risk register for a critical system upgrade. They notice several entries describing generic risks such as 'system failure' or 'data loss' without specifying the cause, affected assets, or potential impact. Which aspect of effective risk scenario development is MOST lacking in these entries?

  1. AAlignment with organizational risk appetite
  2. BQuantification of potential financial impact
  3. CDetailed identification of risk sources and events
  4. DClear ownership for risk response actions
Show answer & explanation

Correct answer: C. Detailed identification of risk sources and events

Effective risk scenarios detail the risk source, the event, and the impact. Generic entries like 'system failure' or 'data loss' without specific causes, affected assets, or potential impacts indicate a lack of detailed identification of the risk sources and events, making them less actionable and difficult to analyze.

Why the other options are wrong

  • A. Alignment with risk appetite (D) is a strategic decision for risk treatment, not a foundational element of how a risk scenario is initially described.
  • B. Quantification of financial impact (C) is a subsequent step in risk analysis; the immediate issue is the lack of specific detail in the scenario itself.
  • D. While important, clear ownership is typically assigned after a risk is sufficiently detailed and understood, not a primary component of its initial identification and description.

Risk Scenario Detail

A well-defined risk scenario clearly describes the threat, the vulnerability, the asset at risk, the event that could occur, and the potential impact.

  • Answers 'what can happen?', 'how?', and 'what are the consequences?'.
  • Makes risks actionable and measurable.
  • Avoids vague or generic descriptions.

Memory trick: A good scenario is a STORY: Source, Threat, Event, Impact.

More IT Risk Assessment questions