CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A manufacturing company is assessing the risk of a cyber-attack disrupting its production line. The likelihood of such an event is estimated to be 'Medium' (3 on a scale of 1-5), and the impact is rated as 'High' (4 on a scale of 1-5) due to significant financial losses and reputational damage. Using a qualitative risk matrix, what would be the MOST appropriate risk level designation?

  1. AHigh
  2. BLow
  3. CModerate
  4. DExtreme
Show answer & explanation

Correct answer: A. High

In a typical qualitative risk matrix, a 'Medium' likelihood combined with a 'High' impact would result in a 'High' risk level. This indicates a significant risk that warrants attention and potential mitigation.

Why the other options are wrong

  • B. Low risk would typically result from low likelihood and low impact combinations.
  • C. Moderate risk might be a medium-medium or low-high combination, but medium-high is generally higher.
  • D. Extreme risk is usually reserved for very high likelihood and very high impact scenarios.

Qualitative Risk Matrix

A tool used in risk analysis to plot the likelihood of a risk occurrence against its potential impact, resulting in a qualitative risk level (e.g., Low, Medium, High).

  • Simplifies complex risk data for decision-making.
  • Uses descriptive terms rather than numerical values for likelihood and impact.
  • Provides a visual representation of risk prioritization.

Memory trick: Matrix crossroads: likelihood meets impact, and a risk level is born.

More IT Risk Assessment questions