ISP Security Risk Management 2 — Questions and Answers
Question 1: Which risk treatment option involves sharing the financial impact of a risk with a third party such as an insurance provider?
- Risk avoidance
- Risk transference (Correct answer)
- Risk acceptance
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, typically through insurance or contracts.
Question 2: In the ASIS Risk Analysis framework, what does the term 'vulnerability' specifically refer to?
- The likelihood that a threat will occur
- A weakness that could be exploited by a threat (Correct answer)
- The potential loss resulting from an incident
- The cost of implementing countermeasures
Correct answer: A weakness that could be exploited by a threat
A vulnerability is a weakness or gap in a security system that a threat agent can exploit to cause harm.
Question 3: A facility security manager discovers that an access control system has not been updated in three years. This situation is best classified as which type of risk factor?
- Threat
- Hazard
- Vulnerability (Correct answer)
- Consequence
Correct answer: Vulnerability
An outdated access control system represents a vulnerability — a weakness in the security posture that increases exposure to threats.
Question 4: Which qualitative risk analysis method uses structured brainstorming among subject-matter experts to estimate likelihood and impact?
- Monte Carlo simulation
- Delphi technique (Correct answer)
- Fault tree analysis
- Annualized loss expectancy calculation
Correct answer: Delphi technique
The Delphi technique gathers consensus estimates from experts through iterative anonymous rounds, making it a qualitative assessment approach.
Question 5: Under the General Duty Clause of OSHA, employers in industrial settings are required to:
- Conduct annual security audits audited by a certified third party
- Provide a workplace free from recognized hazards likely to cause death or serious harm (Correct answer)
- Maintain a minimum of two armed security officers per shift
- Submit risk assessments to OSHA quarterly
Correct answer: Provide a workplace free from recognized hazards likely to cause death or serious harm
The General Duty Clause requires employers to provide a workplace free from recognized serious hazards, forming the baseline obligation for industrial security.
Question 6: When prioritizing security countermeasures, the concept of 'cost-benefit analysis' requires that the cost of a countermeasure:
- Never exceed 10% of the asset value
- Be less than or equal to the risk it reduces (Correct answer)
- Be approved by both security and finance departments
- Match the industry-average expenditure for similar controls
Correct answer: Be less than or equal to the risk it reduces
A countermeasure is justified when its implementation cost does not exceed the reduction in expected loss it provides.
Question 7: Which of the following best describes 'residual risk' in an industrial security context?
- Risk that has been fully eliminated by countermeasures
- Risk transferred to a third-party insurer
- Risk that remains after controls have been applied (Correct answer)
- Risk identified but not yet evaluated
Correct answer: Risk that remains after controls have been applied
Residual risk is the level of risk that persists after all feasible security controls and mitigation measures have been implemented.
Which risk treatment option involves sharing the financial impact of a risk with a third party such as an insurance provider?