SSP Risk Evaluation & Management 4 — Questions and Answers
Question 1: Under the NIST Risk Management Framework (RMF), what is the purpose of the 'Authorize' step?
- A senior official formally accepts the risk of operating an information system based on the implemented controls (Correct answer)
- IT staff are authorized to begin implementing security controls on a new system
- Users receive authorization credentials to access the system after security review
- The organization is authorized by a regulatory body to process sensitive data
Correct answer: A senior official formally accepts the risk of operating an information system based on the implemented controls
In NIST RMF, the Authorize step requires an Authorizing Official to review residual risk and formally accept it before system operation.
Question 2: A security practitioner is applying ISO 31000 principles. Which statement BEST reflects the standard's view on risk management integration?
- Risk management should be embedded in all organizational processes and decision-making, not siloed in a security department (Correct answer)
- Risk management is primarily a compliance function that reports to legal and audit
- Risk management should focus exclusively on threats with a high probability of occurrence
- Risk management frameworks must be standardized across all industries without customization
Correct answer: Risk management should be embedded in all organizational processes and decision-making, not siloed in a security department
ISO 31000 emphasizes that risk management must be integrated into the organization's governance, strategy, planning, and operations—not treated as a separate function.
Question 3: An organization conducts a Failure Mode and Effects Analysis (FMEA) on a physical access control system. What is the PRIMARY output of this analysis?
- A prioritized list of failure modes ranked by their severity, occurrence frequency, and detectability (Correct answer)
- A schedule for replacing aging access control hardware over the next five years
- A compliance report demonstrating adherence to physical security standards
- An incident response plan for when the access control system fails
Correct answer: A prioritized list of failure modes ranked by their severity, occurrence frequency, and detectability
FMEA produces a risk priority number (RPN) for each failure mode by combining severity, occurrence, and detection ratings to drive mitigation priorities.
Question 4: A practitioner is evaluating supply chain risk. A critical vendor processes sensitive personnel data. The vendor's SOC 2 Type II report is 18 months old. What risk does this present?
- The report may not reflect the vendor's current control environment, leaving undetected gaps (Correct answer)
- The vendor is automatically non-compliant because SOC 2 reports expire after 12 months
- The organization must terminate the vendor relationship immediately per regulatory requirements
- The report is still valid because SOC 2 Type II covers a historical audit period
Correct answer: The report may not reflect the vendor's current control environment, leaving undetected gaps
An 18-month-old SOC 2 report may not capture control changes, incidents, or new risks, creating uncertainty about current control effectiveness.
Question 5: When applying the 'bowtie' risk analysis model, what do the LEFT side and RIGHT side of the bowtie represent respectively?
- Threat sources and causes (left) versus consequences and impacts (right), with the 'knot' being the risk event (Correct answer)
- Preventive controls (left) versus detective controls (right), with the event at center
- Quantitative factors (left) versus qualitative factors (right) in a hybrid analysis
- Asset value (left) versus threat likelihood (right) to calculate risk score
Correct answer: Threat sources and causes (left) versus consequences and impacts (right), with the 'knot' being the risk event
The bowtie model maps causes and threats on the left, the unwanted event at the center knot, and consequences with recovery controls on the right.
Question 6: An organization's risk appetite statement says it will 'accept risks up to $500,000 ALE without mandatory escalation.' A new risk is calculated at $650,000 ALE. Which action is REQUIRED?
- The risk must be escalated to senior leadership or the board for a treatment or acceptance decision (Correct answer)
- The risk must be immediately transferred to an insurer because it exceeds appetite
- The risk can be accepted by the security manager since it is only slightly above threshold
- The risk assessment must be recalculated using a different methodology to lower the ALE
Correct answer: The risk must be escalated to senior leadership or the board for a treatment or acceptance decision
The risk appetite statement defines the escalation trigger; a $650,000 ALE exceeds the $500,000 threshold and mandates senior leadership review.
Question 7: What distinguishes a 'risk scenario' from a simple 'threat statement' in enterprise risk management?
- A risk scenario combines a threat actor, a threat event, a vulnerable asset, and a potential impact into a narrative (Correct answer)
- A risk scenario focuses only on the technical vulnerability while a threat statement includes business context
- A risk scenario is used only in qualitative assessments while threat statements are quantitative
- A risk scenario is a historical incident while a threat statement describes a future possibility
Correct answer: A risk scenario combines a threat actor, a threat event, a vulnerable asset, and a potential impact into a narrative
Risk scenarios are structured narratives integrating threat source, event, asset, and impact to make risks concrete and actionable for decision-makers.
Under the NIST Risk Management Framework (RMF), what is the purpose of the 'Authorize' step?