CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

A software development company is migrating its entire code repository to a new cloud-based version control system. A risk assessment identifies that a critical risk exists if proper access controls are not implemented, potentially leading to unauthorized code modification or intellectual property theft. The risk practitioner recommends implementing multi-factor authentication (MFA) and least privilege access as part of the new system's control design. These controls are primarily designed to address which aspect of the risk?

  1. AInherent Risk
  2. BVelocity
  3. CLikelihood
  4. DImpact
Show answer & explanation

Correct answer: C. Likelihood

Multi-factor authentication (MFA) and least privilege access are security controls specifically designed to make it more difficult for unauthorized individuals to gain access or perform unauthorized actions. By increasing the difficulty of unauthorized access, these controls directly reduce the likelihood or probability of the risk event (unauthorized code modification or IP theft) occurring.

Why the other options are wrong

  • A. Inherent risk is the risk before any controls are applied; these are controls that reduce the inherent risk to residual risk.
  • B. Velocity refers to the speed at which a risk event could materialize once triggered, which is not directly addressed by these access controls.
  • D. Impact refers to the severity of the consequences if the risk materializes; these controls do not reduce the severity of IP theft if it occurs.

Risk Likelihood Reduction

Actions taken to decrease the probability of a risk event occurring.

  • Often involves implementing preventive controls.
  • Examples include access controls, encryption, and training.
  • A key component of risk mitigation strategies.

Memory trick: Controls Affect Likelihood and Impact.

More Risk Response and Reporting questions