QuestionQ914

Risk Response and Reporting

What is the risk practitioner’s BEST action after management has successfully implemented a security information and event management (SIEM) tool?

  • A Review and update key risk indicators (KRIs).
  • B Reassess control effectiveness to determine the level of residual risk.
  • C Reassess the impact of scenarios to reflect use of the new control.
  • D Update the IT risk profile to reflect the change in residual risk.
Explanation

Residual risk is the risk that remains after controls are in place, so the control’s design and operating effectiveness must be reassessed to determine whether and by how much the SIEM reduces risk. The IT risk profile can be updated after that residual-risk assessment is completed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!