Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard

A security auditor is reviewing an organization's risk management framework. The auditor notes that while the organization has identified numerous risks and implemented various controls, there is no formal process for regularly reviewing the effectiveness of these controls or for identifying new threats and vulnerabilities that may have emerged. Which key aspect of a robust risk management program is most critically lacking?

  1. ARisk Assessment Scope
  2. BRisk Appetite Definition
  3. CRisk Monitoring and Review
  4. DRisk Treatment Strategy
Show answer & explanation

Correct answer: C. Risk Monitoring and Review

The scenario explicitly states a lack of 'regularly reviewing the effectiveness of these controls or for identifying new threats and vulnerabilities.' This directly points to the absence of a continuous risk monitoring and review process, which is crucial for adaptive risk management.

Why the other options are wrong

  • A. Risk assessment scope defines the boundaries of the assessment, which the organization seems to have done to identify risks.
  • B. Risk appetite definition outlines the level of risk an organization is willing to accept, which is a foundational element but not the specific missing piece here.
  • D. Risk treatment strategy refers to the plan for addressing risks (mitigate, accept, transfer, avoid), which the organization has implemented controls for, implying a strategy.

Risk Monitoring and Review

The continuous process of tracking identified risks, identifying new risks, evaluating the effectiveness of risk treatment plans, and ensuring that the risk management process remains relevant and effective.

  • Essential for maintaining an adaptive risk management program.
  • Involves regular audits, vulnerability scans, and threat intelligence.
  • Ensures controls remain effective against evolving threats.

Memory trick: Plan, Do, Check, Act: The cycle of risk.

More Risk Management questions