NCIC Risk Management & Mitigation 2 — Questions and Answers
Question 1: In criminal intelligence risk management, which framework is most commonly used to assess threats to law enforcement operations?
- ISO 31000 risk management standard
- CARVER matrix (Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability) (Correct answer)
- SWOT analysis
- Six Sigma DMAIC process
Correct answer: CARVER matrix (Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability)
The CARVER matrix is widely used in law enforcement and military contexts to evaluate targets and vulnerabilities across six weighted dimensions.
Question 2: When conducting a threat vulnerability assessment, the term 'residual risk' refers to:
- The initial risk level before any controls are applied
- The risk remaining after countermeasures have been implemented (Correct answer)
- Risk transferred to another organization through contracts
- Historical risk data from previous incidents
Correct answer: The risk remaining after countermeasures have been implemented
Residual risk is the level of risk that persists after all mitigation strategies and controls have been applied to reduce the original risk.
Question 3: A criminal intelligence analyst identifies that a gang is likely planning an attack but lacks specific timing details. This represents which risk condition?
- Confirmed imminent threat
- Credible threat with incomplete specificity (Correct answer)
- Unsubstantiated rumor
- Historical pattern only
Correct answer: Credible threat with incomplete specificity
A credible threat with incomplete specificity means the source and intent are validated but operational details such as timing or exact target remain unknown.
Question 4: Which mitigation strategy involves shifting the financial consequences of a risk to a third party?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk reduction
Correct answer: Risk transfer
Risk transfer moves the financial or operational burden of a risk to another party, such as through insurance or contractual agreements.
Question 5: In the National Criminal Intelligence Sharing Plan (NCISP), risk prioritization is primarily based on:
- Political sensitivity of the target
- Probability of occurrence combined with potential impact (Correct answer)
- Media coverage likelihood
- Jurisdictional authority of the reporting agency
Correct answer: Probability of occurrence combined with potential impact
NCISP guidance directs analysts to prioritize risks by multiplying or combining the likelihood of an event occurring with its potential consequences.
Question 6: What is the primary purpose of a Continuity of Operations Plan (COOP) in a law enforcement intelligence context?
- To document past criminal incidents for future reference
- To ensure essential intelligence functions continue during a disruption (Correct answer)
- To allocate budget for technology upgrades
- To establish personnel promotion criteria
Correct answer: To ensure essential intelligence functions continue during a disruption
A COOP ensures that mission-critical intelligence operations continue or rapidly resume during emergencies, cyberattacks, or natural disasters.
Question 7: Which of the following best describes 'risk appetite' in an intelligence organization?
- The maximum financial loss an agency can absorb
- The level and type of risk an organization is willing to accept to achieve its objectives (Correct answer)
- The number of active threat cases an agency can manage simultaneously
- The percentage of budget allocated to security measures
Correct answer: The level and type of risk an organization is willing to accept to achieve its objectives
Risk appetite defines the amount and type of risk leadership is willing to tolerate while pursuing mission objectives, guiding decision-making thresholds.
In criminal intelligence risk management, which framework is most commonly used to assess threats to law enforcement operations?