Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A healthcare organization is implementing a new electronic health records (EHR) system. During the risk assessment, they identify that unauthorized access to patient data could lead to severe legal penalties under HIPAA regulations and significant damage to patient trust. They classify this risk as 'High' likelihood and 'High' impact. What concept are they using to categorize and understand the severity of this risk?

  1. ARisk Appetite
  2. BRisk Tolerance
  3. CRisk Matrix
  4. DRisk Register
Show answer & explanation

Correct answer: C. Risk Matrix

A risk matrix is a tool used in qualitative risk assessment to categorize risks based on their likelihood and impact. By classifying the risk as 'High' likelihood and 'High' impact, the organization is utilizing a risk matrix to understand its severity.

Why the other options are wrong

  • A. Risk appetite is the level of risk an organization is willing to accept.
  • B. Risk tolerance is the acceptable deviation from the risk appetite.
  • D. A risk register is a document that lists identified risks and their attributes.

Risk Matrix

A qualitative risk assessment tool that plots risks based on their likelihood (probability) and impact (consequence) to determine their overall severity or priority. It typically uses color-coded cells.

  • Visualizes likelihood vs. impact.
  • Categorizes risk severity.
  • Aids in risk prioritization.

Memory trick: Matrices Register Tolerance for Appetite.

More Risk Management questions