Risk Management & Mitigation Strategies Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation Strategies flashcards as text
Which document formally authorizes an information system to operate despite known risks?
Answer: Authorization to Operate (ATO)
An ATO is a formal decision by an authorizing official to accept the risk of operating a system based on the implemented security controls.
A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed?
Answer: Mean Time to Detect (MTTD)
MTTD measures the average time between when a vulnerability or incident occurs and when it is discovered.
In risk management, 'threat modeling' is best described as:
Answer: A structured process for identifying, enumerating, and prioritizing potential threats to a system
Threat modeling proactively identifies threats, vulnerabilities, and countermeasures during design or assessment to improve security posture.
Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact?
Answer: Accept
Low-likelihood, low-impact risks are typically accepted because the cost of treating them outweighs the expected loss.
A GRC analyst maps controls to specific risks to demonstrate coverage. This activity is known as:
Answer: Control mapping
Control mapping links individual security or compliance controls to the specific risks they address, helping identify gaps and redundancies.
Which international standard provides a framework for information security risk management specifically?
Answer: ISO 27005
ISO 27005 provides guidelines for information security risk management and is designed to support implementation of ISO 27001.
During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed?
Answer: The residual risk profile has changed — lower likelihood, same impact
Reducing likelihood while keeping impact constant lowers the overall residual risk score but does not eliminate the risk.