CRM Risk Assessment & Mitigation 2 — Questions and Answers
Question 1: Which risk assessment methodology assigns numerical values to both the probability and impact of a records-related risk to produce a quantitative risk score?
- Qualitative risk matrix
- Annualized Loss Expectancy (ALE) (Correct answer)
- SWOT analysis
- Delphi technique
Correct answer: Annualized Loss Expectancy (ALE)
ALE calculates risk quantitatively by multiplying the Single Loss Expectancy (SLE) by the Annual Rate of Occurrence (ARO).
Question 2: A records manager discovers that a critical business system has no documented recovery procedure. Which risk treatment option directly addresses this gap?
- Risk avoidance
- Risk transfer
- Risk acceptance
- Risk mitigation (Correct answer)
Correct answer: Risk mitigation
Risk mitigation involves implementing controls—such as creating recovery procedures—to reduce the likelihood or impact of a risk.
Question 3: Under ISO 15489, which element is considered foundational to a records risk assessment?
- Identifying records that support business functions (Correct answer)
- Calculating insurance premiums for lost records
- Surveying employee satisfaction with records systems
- Auditing vendor contracts annually
Correct answer: Identifying records that support business functions
ISO 15489 emphasizes that risk assessment must begin with identifying records that support core business functions and processes.
Question 4: An organization's paper records stored in a flood-prone basement represent which type of risk?
- Compliance risk
- Physical/environmental risk (Correct answer)
- Reputational risk
- Regulatory risk
Correct answer: Physical/environmental risk
Storing records in a flood-prone area is a physical and environmental risk that threatens the integrity and availability of those records.
Question 5: Which control is MOST effective at mitigating the risk of unauthorized access to confidential electronic records?
- Implementing role-based access controls (RBAC) (Correct answer)
- Increasing record retention periods
- Conducting annual records inventories
- Digitizing all paper records
Correct answer: Implementing role-based access controls (RBAC)
RBAC restricts access to records based on a user's role, directly reducing the risk of unauthorized access.
Question 6: A residual risk is best defined as:
- The risk remaining after all mitigation controls have been applied (Correct answer)
- The initial risk identified before any analysis
- A risk transferred to a third-party vendor
- A risk that has already materialized as an incident
Correct answer: The risk remaining after all mitigation controls have been applied
Residual risk is the level of risk that remains after controls have been implemented, which management must accept or further address.
Question 7: Which scenario BEST illustrates the risk of record chain-of-custody failure in a legal matter?
- Emails are auto-deleted after 90 days per a retention schedule
- A litigation hold is issued but records are still purged due to poor communication (Correct answer)
- Legal counsel reviews records before production
- Records are migrated to a new system with metadata intact
Correct answer: A litigation hold is issued but records are still purged due to poor communication
Purging records subject to a litigation hold due to communication failure breaks chain of custody and exposes the organization to spoliation sanctions.
Which risk assessment methodology assigns numerical values to both the probability and impact of a records-related risk to produce a quantitative risk score?