Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium
An organization has implemented a new security information and event management (SIEM) system to aggregate and analyze security logs from across its network. The SIEM is configured to generate alerts for suspicious activities and is regularly reviewed by security analysts. This activity primarily falls under which phase of the risk management lifecycle?
- ARisk Monitoring and Review
- BRisk Treatment
- CRisk Acceptance
- DRisk Assessment
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Monitoring and Review
Implementing a SIEM system and regularly reviewing its alerts is a continuous process designed to detect new threats, ensure controls are effective, and adapt to changes in the risk landscape. This continuous oversight and evaluation are central to the 'Risk Monitoring and Review' phase.
Why the other options are wrong
- B. Risk treatment involves implementing controls (the SIEM itself is a control, but its ongoing use is monitoring).
- C. Risk acceptance is a strategy, not an ongoing operational phase.
- D. Risk assessment is about identifying and analyzing risks initially.
Risk Monitoring and Review
The ongoing process of tracking identified risks, identifying new risks, ensuring the effectiveness of risk controls, and evaluating the overall risk management process.
- Ensures risk strategies remain effective over time.
- Involves continuous oversight and adaptation.
- Includes regular audits, vulnerability scans, and performance reviews.
Memory trick: Monitoring is like a security guard on patrol, always watching.