QuestionQ1283

Risk Assessment

Which of the following should be a risk practitioner’s PRIMARY consideration when assessing the possible impact of an adverse event on corporate information assets?

  • A Authentication and authorization requirements for personnel accessing the assets
  • B Potential regulatory fines as a result of the adverse event
  • C The amount of data processed by the assets
  • D Criticality classification of the assets needed for normal business operations
Explanation

The criticality classification of an information asset establishes its importance to normal business operations. It is therefore the primary basis for assessing the operational impact of an adverse event affecting that asset.

Community Discussion

No comments yet. Be the first to start the discussion!