CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

A global manufacturing company uses a Supervisory Control and Data Acquisition (SCADA) system for its production lines. A recent audit highlighted that the SCADA system, being a legacy system, lacks modern authentication mechanisms and is directly accessible from the corporate network, increasing the risk of unauthorized operational changes. The risk practitioner recommends isolating the SCADA network, implementing a jump server for access, and regularly patching the operating system. These actions primarily aim to address which aspect of the risk?

  1. AIncrease risk appetite
  2. BIncrease risk impact
  3. CReduce risk likelihood
  4. DTransfer risk ownership
Show answer & explanation

Correct answer: C. Reduce risk likelihood

Isolating the network, using a jump server, and patching the system all aim to make it harder for unauthorized users to access and manipulate the SCADA system, thereby reducing the probability or frequency of a successful attack.

Why the other options are wrong

  • A. Increasing risk appetite means the organization is willing to accept more risk, which is contrary to the actions taken.
  • B. Increasing risk impact would make the consequences worse, which is the opposite of the goal.
  • D. Transferring risk ownership would involve another party taking responsibility for the risk, which is not described here.

Risk Likelihood Reduction

Risk likelihood reduction involves implementing controls or actions specifically designed to decrease the probability or frequency of a risk event occurring.

  • Focuses on preventing events.
  • Often involves security controls, process improvements, or training.
  • Distinguished from impact reduction, which lessens consequences.

Memory trick: L-I-C: Likelihood, Impact, Control.

More Risk Response and Reporting questions