CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, potentially leading to credit card data breaches. The risk committee decides to implement endpoint detection and response (EDR) software across all POS terminals and conduct monthly vulnerability scans. Which control objective is primarily addressed by these actions?

  1. AMaintaining system integrity
  2. BEnsuring data availability
  3. COptimizing operational efficiency
  4. DPreventing unauthorized disclosure
Show answer & explanation

Correct answer: D. Preventing unauthorized disclosure

Malware attacks and credit card data breaches directly threaten the confidentiality of sensitive customer data. EDR and vulnerability scans are implemented to prevent the unauthorized disclosure of this information.

Why the other options are wrong

  • A. System integrity is about data accuracy and completeness. While malware can affect integrity, a data breach primarily concerns disclosure.
  • B. While security can indirectly support availability, the primary threat here is data exposure, not system downtime.
  • C. These actions are security measures, not primarily aimed at improving how smoothly operations run.

Control Objectives (Confidentiality)

Specific goals or statements that describe the desired outcome of implementing controls, such as protecting data from unauthorized disclosure.

  • Often linked to CIA triad (Confidentiality, Integrity, Availability)
  • Guides control design and implementation
  • Helps measure control effectiveness

Memory trick: CIA: Confidentiality, Integrity, Availability – a secret agent's job!

More Risk Response and Reporting questions