Summary: Crisc Review Manual 6Th Edition | 9781604203714 | Isaca

Study material generic cover image
  • This + 400k other summaries
  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Use this summary
Remember faster, study better. Scientifically proven.
Trustpilot Logo

Read the summary and the most important questions on CRISC Review Manual 6th Edition | 9781604203714 | Isaca

  • 3 Risk Response and Mitigation (section 2)

  • 3.2 Risk response options

    This is a preview. There are 1 more flashcards available for chapter 3.2
    Show more cards here

  • What is the purpose of defining a risk response?

    To bring risk in line with the defined risk tolerance of the organization as cost-effective as possible, not to eliminate or minimize the risk at all costs.
  • 3.2.1 Risk acceptance

    This is a preview. There are 1 more flashcards available for chapter 3.2.1
    Show more cards here

  • Who makes the decision to accept risk?

    Senior management, in according to the risk appetite and risk tolerance set by senior management, because they are responsible for the impact of a risk event should it occur.
  • What is the goal of risk management?

    Bring risk within acceptable levels as cost-effectively.
  • What risks should be accepted?

    Risks that fall within the organizational risk appetite.
  • Name examples of risk acceptance as a result of risk tolerance.

    1. No controls are available
    2. The costs of the controls would outweigh their benefit
  • What helps the risk practitioner to estimate the true likely incident costs?

    1. Careful review of actuarial data 
    2. The outcomes of similar incidents at other organizations and their resulting impact
  • 3.2.2 Risk mitigation

    This is a preview. There are 1 more flashcards available for chapter 3.2.2
    Show more cards here

  • Name examples of risk mitigation.

    1. Strengthening overall risk management practices, such as risk management processes.
    2. Deploying new technical, management or operational controls.
    3. Installing a new access control system.
    4. Implementing policies or operational procedures.
    5. Developing an effective incident response and business continuity plan (BCP)
    6. Using compensating controls
  • 3.2.3 Risk transfer (sharing)

    This is a preview. There are 1 more flashcards available for chapter 3.2.3
    Show more cards here

  • What is risk transfer?

    A decision to reduce loss by having another organization incur the cost.
  • Name 2 examples of risk transfer.

    1. Insurance
    2. Partnership
  • Why is risk transfer not a complete absolution of blame?

    Long-term costs, like reputational damages ae rarely covered by insurances, for example in case of a data breach.

To read further, please click:

Read the full summary
This summary +380.000 other summaries A unique study tool A rehearsal system for this summary Studycoaching with videos
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart