CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium
An organization is developing a risk scenario for 'Unauthorized Access to Customer Data via a Third-Party Vendor Compromise.' Which of the following elements, if omitted, would MOST likely hinder the effective analysis and response planning for this specific scenario?
- AA list of all third-party vendors used by the organization.
- BThe specific type of customer data that could be accessed and its classification.
- CThe names of the internal stakeholders responsible for vendor management.
- DHistorical data on similar third-party breaches across the industry.
Show answer & explanationAnswer & explanation
Correct answer: B. The specific type of customer data that could be accessed and its classification.
To effectively analyze a risk scenario and plan responses, understanding the specific asset at risk and its criticality is paramount. Knowing the type and classification of customer data directly impacts the severity of the incident and guides the appropriate response, such as notification requirements, recovery efforts, and legal obligations.
Why the other options are wrong
- A. While useful for context, a comprehensive list of all vendors is less critical for *this specific scenario* than knowing what data is at risk.
- C. Identifying responsible stakeholders is important for governance and execution, but the core analysis and planning depends on understanding the data at risk first.
- D. Historical industry data provides context for likelihood but is not as critical for planning specific responses to *this* scenario as knowing the data itself.
Risk Scenario Detail
A detailed description of a potential risk event, including its cause, event, and impact, used for structured risk assessment.
- Should be specific and actionable.
- Includes assets, threats, vulnerabilities, and impacts.
- Guides control selection and response planning.
Memory trick: A good scenario maps out the 'What', 'How', and 'Why' of a risk.