GRC Risk Management & Mitigation Strategies 5 — Questions and Answers
Question 1: Which document formally authorizes an information system to operate despite known risks?
- Risk assessment report
- Authorization to Operate (ATO) (Correct answer)
- System security plan
- Incident response plan
Correct answer: Authorization to Operate (ATO)
An ATO is a formal decision by an authorizing official to accept the risk of operating a system based on the implemented security controls.
Question 2: A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed?
- Mean Time to Detect (MTTD) (Correct answer)
- Mean Time to Remediate (MTTR)
- Recovery Point Objective (RPO)
- Annualized Rate of Occurrence (ARO)
Correct answer: Mean Time to Detect (MTTD)
MTTD measures the average time between when a vulnerability or incident occurs and when it is discovered.
Question 3: In risk management, 'threat modeling' is best described as:
- Creating a list of all possible insurance claims
- A structured process for identifying, enumerating, and prioritizing potential threats to a system (Correct answer)
- Simulating cyberattacks on live production systems
- Assigning dollar values to each identified threat
Correct answer: A structured process for identifying, enumerating, and prioritizing potential threats to a system
Threat modeling proactively identifies threats, vulnerabilities, and countermeasures during design or assessment to improve security posture.
Question 4: Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact?
- Avoid
- Transfer
- Mitigate
- Accept (Correct answer)
Correct answer: Accept
Low-likelihood, low-impact risks are typically accepted because the cost of treating them outweighs the expected loss.
Question 5: A GRC analyst maps controls to specific risks to demonstrate coverage. This activity is known as:
- Control mapping (Correct answer)
- Risk scoring
- Gap analysis
- Residual risk calculation
Correct answer: Control mapping
Control mapping links individual security or compliance controls to the specific risks they address, helping identify gaps and redundancies.
Question 6: Which international standard provides a framework for information security risk management specifically?
- ISO 31000
- ISO 27005 (Correct answer)
- ISO 9001
- ISO 22301
Correct answer: ISO 27005
ISO 27005 provides guidelines for information security risk management and is designed to support implementation of ISO 27001.
Question 7: During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed?
- The inherent risk has been eliminated
- The residual risk profile has changed — lower likelihood, same impact (Correct answer)
- The risk has been fully transferred
- The risk's velocity has increased
Correct answer: The residual risk profile has changed — lower likelihood, same impact
Reducing likelihood while keeping impact constant lowers the overall residual risk score but does not eliminate the risk.
Which document formally authorizes an information system to operate despite known risks?