CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard
A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified that these systems are highly vulnerable to cyberattacks due to outdated software and network isolation challenges. The company decides to invest in a dedicated OT security monitoring solution and implement strict access controls. Furthermore, it establishes a formal incident response plan specifically for OT systems. This comprehensive approach to risk management for OT systems primarily demonstrates the application of:
- AControl documentation consistency
- BCentralized risk ownership
- CIntegrated risk management
- DRisk reporting standardization
Show answer & explanationAnswer & explanation
Correct answer: C. Integrated risk management
Integrated risk management involves a holistic and coordinated approach to managing all types of risks across an organization. By applying a dedicated and comprehensive strategy (monitoring, access controls, incident response) specifically tailored to OT systems, the company is integrating OT risk management into its overall enterprise risk management framework, rather than treating it in isolation.
Why the other options are wrong
- A. Control documentation consistency is important, but it's a component of good governance, not the overarching risk management approach demonstrated here.
- B. Centralized risk ownership refers to a single point of accountability for risk, not the comprehensive strategy itself.
- D. Risk reporting standardization is about the format and content of reports, not the underlying approach to managing a specific risk domain.
Integrated Risk Management (IRM)
A holistic approach that aims to unify and coordinate all risk management activities across an organization, ensuring a consistent view and response to risks.
- Breaks down risk silos
- Provides a comprehensive view of risk
- Aligns risk management with business objectives
Memory trick: ERM: Everyone's Risk Management – Unified!