GRC Risk Management & Mitigation Strategies 4 — Questions and Answers
Question 1: Which key performance indicator (KPI) in risk management measures how quickly an organization can restore operations after a disruption?
- Recovery Time Objective (RTO) (Correct answer)
- Recovery Point Objective (RPO)
- Mean Time Between Failures (MTBF)
- Risk Tolerance Threshold (RTT)
Correct answer: Recovery Time Objective (RTO)
RTO defines the maximum acceptable length of time to restore a business function after an incident.
Question 2: A third-party vendor stores sensitive customer data on behalf of your organization. Which risk category does this primarily represent?
- Strategic risk
- Operational risk
- Third-party/supply chain risk (Correct answer)
- Compliance risk
Correct answer: Third-party/supply chain risk
Risks arising from reliance on external vendors or partners are classified as third-party or supply chain risks.
Question 3: In the NIST Risk Management Framework (RMF), what is the correct order of the first three steps?
- Categorize → Select → Implement
- Identify → Assess → Respond
- Prepare → Categorize → Select (Correct answer)
- Assess → Authorize → Monitor
Correct answer: Prepare → Categorize → Select
NIST RMF begins with Prepare, then Categorize (the system), then Select (security controls), followed by Implement, Assess, Authorize, and Monitor.
Question 4: Which risk mitigation technique involves duplicating critical systems to ensure availability during a failure?
- Encryption
- Redundancy (Correct answer)
- Patch management
- User training
Correct answer: Redundancy
Redundancy reduces the risk of system failure by maintaining backup components or systems that can take over if the primary fails.
Question 5: An organization uses scenario analysis to evaluate risks. What is the primary benefit of this approach?
- It eliminates uncertainty about future events
- It explores plausible future situations to understand potential impacts (Correct answer)
- It provides legally binding risk thresholds
- It replaces the need for a risk register
Correct answer: It explores plausible future situations to understand potential impacts
Scenario analysis helps organizations anticipate various possible futures and evaluate how they would respond, improving preparedness.
Question 6: Which type of risk arises from inadequate or failed internal processes, people, systems, or external events?
- Strategic risk
- Operational risk (Correct answer)
- Reputational risk
- Credit risk
Correct answer: Operational risk
Operational risk, as defined by Basel II/III, stems from breakdowns in internal processes, human errors, system failures, or external events.
Question 7: What is the purpose of a risk owner in a GRC program?
- To insure the organization against the risk
- To be accountable for managing and monitoring a specific risk (Correct answer)
- To report the risk directly to regulators
- To calculate the monetary value of the risk
Correct answer: To be accountable for managing and monitoring a specific risk
A risk owner is an individual assigned responsibility for ensuring that a specific risk is adequately identified, assessed, and treated.
Which key performance indicator (KPI) in risk management measures how quickly an organization can restore operations after a disruption?