CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy
An organization has implemented a new access control system. As part of control monitoring, the risk practitioner reviews audit logs daily for failed login attempts. This activity is primarily intended to assess which of the following aspects of the control?
- ACost-benefit
- BMaturity
- CEffectiveness
- DEfficiency
Show answer & explanationAnswer & explanation
Correct answer: C. Effectiveness
Reviewing audit logs for failed login attempts directly assesses whether the access control system is successfully preventing unauthorized access attempts and detecting anomalies, which pertains to the effectiveness of the control in achieving its intended security objective. While efficiency, cost-benefit, and maturity are important, they are not the primary focus of this specific monitoring activity.
Why the other options are wrong
- A. Cost-benefit analyzes the economic value of the control versus its cost, which is not directly assessed by reviewing audit logs.
- B. Maturity relates to the sophistication and optimization of the control process, not its immediate operational success in preventing incidents.
- D. Efficiency relates to the resources used by the control (e.g., time, money), which is not the primary focus of checking failed logins.
Control Effectiveness
The degree to which a control achieves its intended security objective.
- Measured by whether the control mitigates the identified risk.
- Often assessed through testing, monitoring, and audit reviews.
- A crucial metric for ongoing risk management.
Memory trick: Monitor Exactly For Effective Results.