ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

An organization is conducting a comprehensive review of its cybersecurity posture. They are evaluating the likelihood of various threats exploiting vulnerabilities and the resulting impact on business operations. The overall process of identifying, assessing, and treating these potential negative events is known as:

  1. AIncident Response
  2. BRisk Management
  3. CSecurity Audit
  4. DCompliance Management
Show answer & explanation

Correct answer: B. Risk Management

Risk management is the systematic process of identifying, assessing, and treating risks to an organization's assets. It involves understanding threats, vulnerabilities, likelihood, and impact.

Why the other options are wrong

  • A. Incident response is the process of handling security incidents, occurring after a risk has materialized.
  • C. A security audit is an examination of an organization's information systems to determine if they are operating as expected and in compliance with policies.
  • D. Compliance management ensures adherence to external laws and internal policies, which is part of risk management but not the overall process described.

Risk Management

The systematic process of identifying, assessing, and controlling threats to an organization's capital and earnings.

  • Involves identification, assessment, and treatment of risks.
  • A continuous process, not a one-time event.
  • Aims to balance risk with cost of controls.

Memory trick: Manage risks, don't just react.

More Security Principles questions