RIMS Risk Assessment & Mitigation 3 — Questions and Answers
Question 1: When conducting a Business Impact Analysis (BIA), which metric represents the maximum time a business process can be disrupted before causing unacceptable harm?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the longest period a business function can be unavailable before the organization suffers irreversible consequences.
Question 2: A risk manager uses scenario analysis to evaluate the impact of a major cyberattack on operations. What is the PRIMARY purpose of this technique?
- To eliminate all cyber risks through preventive controls
- To transfer cyber liability to an insurer
- To understand potential outcomes and test response readiness (Correct answer)
- To comply with SEC cybersecurity disclosure rules
Correct answer: To understand potential outcomes and test response readiness
Scenario analysis explores hypothetical 'what-if' situations to understand potential impacts and prepare response strategies, improving organizational resilience.
Question 3: Which of the following is a characteristic of 'black swan' events that makes them challenging for traditional risk models?
- They occur frequently and are easily predicted
- They have high probability and low impact
- They are rare, unpredictable, and have extreme consequences (Correct answer)
- They are covered by standard insurance policies
Correct answer: They are rare, unpredictable, and have extreme consequences
Black swan events are statistically rare, lie outside normal expectations, and carry massive impact — making them very difficult for conventional probability-based models to anticipate.
Question 4: A risk heat map that shows many risks clustered in the high-likelihood/high-impact quadrant signals that the organization should:
- Accept all risks since they are well-documented
- Prioritize immediate treatment actions and escalate to senior leadership (Correct answer)
- Transfer every risk to a captive insurer
- Remove low-priority risks from the register
Correct answer: Prioritize immediate treatment actions and escalate to senior leadership
Risks in the high-likelihood/high-impact quadrant require urgent treatment and executive attention because they pose the greatest threat to organizational objectives.
Question 5: In ERM, a 'risk owner' is defined as:
- The CEO who approves the enterprise risk policy
- The individual accountable for managing a specific risk and implementing controls (Correct answer)
- The external auditor who validates risk disclosures
- The insurer who covers the financial consequences of a risk
Correct answer: The individual accountable for managing a specific risk and implementing controls
A risk owner is the designated individual with the authority and accountability to manage, monitor, and report on a specific risk within the risk register.
Question 6: Which risk treatment option is MOST appropriate when the cost of controlling a risk exceeds the potential loss from the risk itself?
- Risk avoidance
- Risk reduction
- Risk acceptance (retention) (Correct answer)
- Risk transfer
Correct answer: Risk acceptance (retention)
When control costs exceed potential losses, risk acceptance (retention) is economically rational — the organization consciously decides to absorb the risk rather than overspend on mitigation.
Question 7: A supply chain risk assessment reveals a single-source supplier for a critical component. The BEST mitigation strategy is to:
- Accept the concentration risk and insure the inventory
- Qualify alternative suppliers to reduce single-source dependency (Correct answer)
- Avoid using the component in all future products
- Transfer supply risk to the supplier via contract penalties
Correct answer: Qualify alternative suppliers to reduce single-source dependency
Qualifying alternative suppliers directly addresses the single-source concentration risk by building redundancy and reducing dependency on one vendor.
When conducting a Business Impact Analysis (BIA), which metric represents the maximum time a business process can be disrupted before causing unacceptable harm?