CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A manufacturing company uses a Supervisory Control and Data Acquisition (SCADA) system for its production lines. A recent risk assessment identified a critical vulnerability in the SCADA system's remote access module that could allow unauthorized control over operations, leading to significant safety and production risks. The company decides to implement a two-factor authentication (2FA) system, restrict remote access to specific IP addresses, and conduct weekly security patch reviews. These actions primarily address which aspect of the risk?

  1. AThe likelihood of an unauthorized remote access event.
  2. BThe external regulatory compliance requirements.
  3. CThe financial impact of a successful attack.
  4. DThe recovery time objective (RTO) after an incident.
Show answer & explanation

Correct answer: A. The likelihood of an unauthorized remote access event.

Implementing 2FA, IP restrictions, and patch reviews are all preventive controls designed to make it harder for an unauthorized remote access event to occur, thereby reducing the probability or frequency (likelihood) of the risk materializing.

Why the other options are wrong

  • B. While these actions might contribute to compliance, their primary goal is risk reduction, not merely fulfilling a check-box requirement.
  • C. These controls do not directly reduce the financial impact, but rather prevent the event that would cause the impact.
  • D. These are preventive measures, not recovery measures. RTO relates to how quickly systems can be restored after an incident, not preventing the incident itself.

Preventive Controls

Controls designed to stop undesirable events from happening in the first place, thereby reducing the likelihood of a risk event occurring.

  • Aimed at preventing errors, omissions, or malicious acts.
  • Operate before a risk event can materialize.
  • Examples include access controls, encryption, and training.

Memory trick: Prevent Before, Detect During, Correct After.

More Risk Response and Reporting questions