A city CIO wants a reusable definition for the risk that unpatched internet-facing civic apps can be exploited. What record should the risk team author first?
Select an answer to reveal the explanation.
Short Explanation
You need a reusable recipe card, not a one-time sticky note. Author the risk statement for that exploitation scenario so you can apply it across apps later.
Full Explanation
Risk statement definition is a core lifecycle step: a reusable statement captures the risk language that can later be scoped to entities. Audit engagements, transient incidents, or acknowledgments alone do not create that reusable risk definition.